PT-2026-64146 · Amazon · Aws-Smithy-Http-Server
CVE-2026-16756
·
Published
2026-07-23
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
aws-smithy-http-server versions prior to 0.66.5
Description
An issue in the default
serve() path of Amazon aws-smithy-http-server allows unauthenticated Slowloris denial of service. This occurs due to missing connection and header-read timeouts and the absence of a concurrent-connection cap, which enables remote attackers to exhaust server sockets and tasks by opening numerous connections and sending partial requests that are never completed. Slowloris is a type of denial-of-service attack that keeps many connections to the target web server open and holds them open as long as possible.Recommendations
Upgrade to version 0.66.5 or later.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Smithy-Http-Server