Denial of Service Vulnerability in Amazon AWS Smithy HTTP Server
CVE-2026-16756

8.7HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
23 July 2026

What is CVE-2026-16756?

The AWS Smithy HTTP Server lacks essential connection and header-read timeouts, and it does not impose a limit on concurrent connections. This oversight can enable remote attackers to exploit the default serve() path by opening numerous connections and transmitting incomplete requests. As a result, server resources such as sockets and tasks may be exhausted, leading to a denial of service. Users are advised to update to version 0.66.5 or later to mitigate this risk.

Affected Version(s)

aws-smithy-http-server 0 <= 0.66.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.