HIGH 7.5 GitHub
CVE-2026-18140
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated serv
### Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists which allows uncontrolled recursion in the unknown-key skip path of the Amazon aws-smithy-json runtime crate in versions 0.62.6 and earlier.
### Impact
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy
Affected Products
- rust/aws-smithy-json <= 0.62.6
References
- https://github.com/advisories/GHSA-8ffr-xgwf-xj56
- https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-8ffr-xgwf-xj56
- https://nvd.nist.gov/vuln/detail/CVE-2026-18140
- https://github.com/smithy-lang/smithy-rs/pull/4685
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-02 via GitHub. Affected: rust/aws-smithy-json <= 0.62.6.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.