To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later. | |
| Title | Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service | |
| First Time appeared |
Aws
Aws aws-smithy-http-server |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:aws:aws-smithy-http-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-smithy-http-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-23T19:03:57.617Z
Reserved: 2026-07-23T13:10:13.818Z
Link: CVE-2026-16756
Updated: 2026-07-23T19:03:52.252Z
No data.
No data.
OpenCVE Enrichment
No data.