CVE-2026-16756

Summary

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.

To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.

Affected Software

VendorProductVersion RangeStatus
AWSaws-smithy-http-server0 <= 0.66.4affected

Weaknesses

  • CWE-770: CWE-770 Allocation of resources without limits or throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References