CVE-2026-18140: 
Rust vulnerability analysis and mitigation

Overview

CVE-2026-18140 is an uncontrolled recursion vulnerability in the aws-smithy-json Rust runtime crate that allows remote unauthenticated attackers to cause a denial of service via stack exhaustion. It affects all versions of aws-smithy-json from 0.32.0 through 0.62.6, used by the smithy-rs code generation framework that powers the AWS SDK for Rust and custom smithy-rs generated servers. The vulnerability was published on July 30, 2026, with a patch released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (AWS Security Bulletin, GitHub Advisory).

Technical details

The root cause is uncontrolled recursion (CWE-674) in the unknown-key skip path of the aws-smithy-json deserializer. When the smithy-rs code generator produces struct deserializers, it invokes this skip path to handle JSON keys not recognized by the schema; if the input JSON contains deeply nested objects or arrays, the deserializer recurses without bound, exhausting the call stack and causing the process to abort. Because this skip path is invoked from every generated struct deserializer, any smithy-rs generated server endpoint that accepts JSON input is potentially affected. No authentication or special privileges are required, and the attack can be triggered with a single, small HTTP request containing a deeply nested JSON payload (AWS Security Bulletin, GitHub Advisory).

Impact

Successful exploitation causes the targeted smithy-rs generated server process to abort due to stack exhaustion, resulting in a complete loss of availability for the affected service. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Because the attack requires only a single small HTTP request and no authentication, it can be trivially repeated to keep a service continuously unavailable, and any internet-facing smithy-rs generated server (including those built on the AWS SDK for Rust) is at risk (AWS Security Bulletin, GitHub Advisory).

Exploitability

No public proof-of-concept exploit is known at this time, and there is no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies exploitation as "none" but notes the attack is automatable. The EPSS score is approximately 0.0044 (0.44%), reflecting low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (AWS Security Bulletin, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing HTTP services built with smithy-rs generated servers (e.g., services using the AWS SDK for Rust or custom Smithy-defined APIs). These may be discoverable via service banners, API documentation, or cloud service enumeration.
  2. Craft malicious payload: Construct a small HTTP request body containing a deeply nested JSON object or array (e.g., {"a":{"a":{"a":{...}}}} repeated hundreds or thousands of levels deep) targeting any JSON-accepting endpoint.
  3. Send the request: Transmit the crafted HTTP POST (or other method) request to any endpoint of the target smithy-rs generated server. No authentication token or special headers are required.
  4. Trigger stack exhaustion: The server's generated struct deserializer invokes the unknown-key skip path recursively for each nesting level, exhausting the thread/process stack and causing the server process to abort.
  5. Repeat for sustained DoS: Because the attack requires minimal resources, it can be repeated in rapid succession to prevent service recovery (AWS Security Bulletin, GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests with small body sizes but abnormally deep JSON nesting directed at smithy-rs generated server endpoints; repeated requests from the same source IP causing service restarts.
  • Logs: Application or system logs showing sudden process termination with stack overflow or stack exhaustion errors from the Rust runtime; repeated service crash/restart events in process supervision logs (e.g., systemd, supervisord).
  • Process: Unexpected termination of smithy-rs generated server processes (e.g., SIGSEGV or SIGABRT signals related to stack overflow in Rust binaries); abnormally high process restart rates observed in container orchestration platforms (e.g., Kubernetes pod crash loops).

Mitigation and workarounds

The only remediation is to upgrade aws-smithy-json to version 0.62.7 or later and rebuild all affected applications — AWS has confirmed there are no configuration-based workarounds. Users of the AWS SDK for Rust or any smithy-rs generated server should update their Cargo.toml dependency, run cargo update, rebuild, and redeploy. As a temporary network-layer mitigation while patching, operators may consider implementing request body size limits or JSON depth validation at a reverse proxy or API gateway to reject excessively nested payloads (AWS Security Bulletin, GitHub Advisory).

Community reactions

The vulnerability was noted on Mastodon security feeds shortly after disclosure, and the AWS security bulletin was picked up by automated threat intelligence aggregators and CISA's vulnerability bulletin (SB26-215). No significant independent researcher commentary or media coverage beyond standard vulnerability tracking has been observed at this time (AWS Security Bulletin).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Fixed

OpenShift

el9:openshift-logging/vector-rhel9-0:v6.2.13

Fixed

RHEL 9

:extensions:goose/goose-0:1.38.0-1.el9_8

Fixed

RHEL 10

goose-0:1.38.0-1.el10_2.src

Fixed

Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

RUSTSEC-2026-0327CRITICAL9.3
  • Rust logoRust
  • wasmtime
NoYesOct 02, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
RUSTSEC-2026-0326MEDIUM5.7
  • Rust logoRust
  • wasmtime
NoYesOct 02, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026
CVE-2026-104855LOW2
  • Rust logoRust
  • wasmtime
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management