PT-2026-64146 · Amazon · Aws-Smithy-Http-Server

CVE-2026-16756

·

Published

2026-07-23

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions aws-smithy-http-server versions prior to 0.66.5
Description An issue in the default serve() path of Amazon aws-smithy-http-server allows unauthenticated Slowloris denial of service. This occurs due to missing connection and header-read timeouts and the absence of a concurrent-connection cap, which enables remote attackers to exhaust server sockets and tasks by opening numerous connections and sending partial requests that are never completed. Slowloris is a type of denial-of-service attack that keeps many connections to the target web server open and holds them open as long as possible.
Recommendations Upgrade to version 0.66.5 or later.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16756
GHSA-JVXP-QMX7-GJPX

Affected Products

Aws-Smithy-Http-Server