Uncontrolled Recursion Vulnerability in Smithy-RS Framework Affecting AWS SDK for Rust
CVE-2026-15957

8.7HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
21 July 2026

What is CVE-2026-15957?

The Smithy-RS framework, essential for generating Rust-based HTTP clients and servers, exposes an uncontrolled recursion vulnerability. This vulnerability exists within the JSON, CBOR, and XML deserializers, enabling attackers to exploit a recursive model shape through small requests with deeply nested data. Such exploitation can result in denial of service by causing process aborts due to stack exhaustion. To protect against this vulnerability, users are advised to upgrade to the latest version of aws-sdk-rust and regenerate custom servers using the updated smithy-rs code generator.

Affected Version(s)

aws-sdk-rust 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.