High severityNVD Advisory· Published Jul 23, 2026· Updated Jul 23, 2026
Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
CVE-2026-16756
Description
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.
To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aws-smithy-http-servercrates.io | < 0.66.5 | 0.66.5 |
Affected products
1- Range: >=0.66.5
Patches
Vulnerability mechanics
References
6- crates.io/crates/aws-smithy-http-server/0.66.5ghsarelease-notespatchWEB
- aws.amazon.com/security/security-bulletins/2026-064-aws/mitrevendor-advisory
- github.com/advisories/GHSA-jvxp-qmx7-gjpxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-16756ghsaADVISORY
- aws.amazon.com/security/security-bulletins/2026-064-awsghsaWEB
- github.com/smithy-lang/smithy-rs/security/advisories/GHSA-jvxp-qmx7-gjpxghsarelease-notesWEB
News mentions
0No linked articles in our index yet.