
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18140 is an uncontrolled recursion vulnerability in the aws-smithy-json Rust runtime crate that allows remote unauthenticated attackers to cause a denial of service via stack exhaustion. It affects all versions of aws-smithy-json from 0.32.0 through 0.62.6, used by the smithy-rs code generation framework that powers the AWS SDK for Rust and custom smithy-rs generated servers. The vulnerability was published on July 30, 2026, with a patch released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (AWS Security Bulletin, GitHub Advisory).
The root cause is uncontrolled recursion (CWE-674) in the unknown-key skip path of the aws-smithy-json deserializer. When the smithy-rs code generator produces struct deserializers, it invokes this skip path to handle JSON keys not recognized by the schema; if the input JSON contains deeply nested objects or arrays, the deserializer recurses without bound, exhausting the call stack and causing the process to abort. Because this skip path is invoked from every generated struct deserializer, any smithy-rs generated server endpoint that accepts JSON input is potentially affected. No authentication or special privileges are required, and the attack can be triggered with a single, small HTTP request containing a deeply nested JSON payload (AWS Security Bulletin, GitHub Advisory).
Successful exploitation causes the targeted smithy-rs generated server process to abort due to stack exhaustion, resulting in a complete loss of availability for the affected service. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Because the attack requires only a single small HTTP request and no authentication, it can be trivially repeated to keep a service continuously unavailable, and any internet-facing smithy-rs generated server (including those built on the AWS SDK for Rust) is at risk (AWS Security Bulletin, GitHub Advisory).
No public proof-of-concept exploit is known at this time, and there is no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies exploitation as "none" but notes the attack is automatable. The EPSS score is approximately 0.0044 (0.44%), reflecting low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (AWS Security Bulletin, GitHub Advisory).
{"a":{"a":{"a":{...}}}} repeated hundreds or thousands of levels deep) targeting any JSON-accepting endpoint.SIGSEGV or SIGABRT signals related to stack overflow in Rust binaries); abnormally high process restart rates observed in container orchestration platforms (e.g., Kubernetes pod crash loops).The only remediation is to upgrade aws-smithy-json to version 0.62.7 or later and rebuild all affected applications — AWS has confirmed there are no configuration-based workarounds. Users of the AWS SDK for Rust or any smithy-rs generated server should update their Cargo.toml dependency, run cargo update, rebuild, and redeploy. As a temporary network-layer mitigation while patching, operators may consider implementing request body size limits or JSON depth validation at a reverse proxy or API gateway to reject excessively nested payloads (AWS Security Bulletin, GitHub Advisory).
The vulnerability was noted on Mastodon security feeds shortly after disclosure, and the AWS security bulletin was picked up by automated threat intelligence aggregators and CISA's vulnerability bulletin (SB26-215). No significant independent researcher commentary or media coverage beyond standard vulnerability tracking has been observed at this time (AWS Security Bulletin).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."