LOWVulnerability
Global

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

·Source: AWS Security Bulletins

Updated:

Executive Summary

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations.

Analysis

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris" denial of service. Impacted versions: aws-smithy-http-server Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Indicators of Compromise (1)

CVE (1)
CVE-2026-16756
Source Attribution

Originally published by AWS Security Bulletins on Jul 23, 2026.

Related Threats