Uncontrolled Recursion Vulnerability in Smithy-RS Framework Affecting AWS SDK for Rust
CVE-2026-15957
8.7HIGH
What is CVE-2026-15957?
The Smithy-RS framework, essential for generating Rust-based HTTP clients and servers, exposes an uncontrolled recursion vulnerability. This vulnerability exists within the JSON, CBOR, and XML deserializers, enabling attackers to exploit a recursive model shape through small requests with deeply nested data. Such exploitation can result in denial of service by causing process aborts due to stack exhaustion. To protect against this vulnerability, users are advised to upgrade to the latest version of aws-sdk-rust and regenerate custom servers using the updated smithy-rs code generator.
Affected Version(s)
aws-sdk-rust 0
