High severity7.5NVD Advisory· Published Jul 23, 2026· Updated Aug 12, 2026
CVE-2026-16756
CVE-2026-16756
Description
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.
To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aws-smithy-http-servercrates.io | < 0.66.5 | 0.66.5 |
Affected products
2- Range: >=0.66.5
- Range: >=0.66.5
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-jvxp-qmx7-gjpxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-16756ghsaADVISORY
- aws.amazon.com/security/security-bulletins/2026-064-awsghsaWEB
- crates.io/crates/aws-smithy-http-server/0.66.5nvdWEB
- github.com/smithy-lang/smithy-rs/security/advisories/GHSA-jvxp-qmx7-gjpxnvdWEB
- aws.amazon.com/security/security-bulletins/2026-064-aws/nvd
News mentions
0No linked articles in our index yet.