Denial of Service Vulnerability in Amazon AWS Smithy HTTP Server
CVE-2026-16756
8.7HIGH
What is CVE-2026-16756?
The AWS Smithy HTTP Server lacks essential connection and header-read timeouts, and it does not impose a limit on concurrent connections. This oversight can enable remote attackers to exploit the default serve() path by opening numerous connections and transmitting incomplete requests. As a result, server resources such as sockets and tasks may be exhausted, leading to a denial of service. Users are advised to update to version 0.66.5 or later to mitigate this risk.
Affected Version(s)
aws-smithy-http-server 0 <= 0.66.4
