bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: aws-smithy-json

show all
Friday, July 31, 2026

Critical DoS Vulnerability in smithy-rs JSON Parser

aws-smithy-json has a nasty uncontrolled recursion bug in its unknown-key skip path that lets unauthenticated attackers crash smithy-rs generated servers with a denial of service attack. This affects all servers built with the vulnerable library. You should patch immediately—no user interaction needed to trigger the exploit. Check AWS Security Bulletin for detailed mitigation steps and patched versions.

> source: aws.amazon.com