CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers

Published 2026-08-20T21:35:57Z909912d5e468a3d4b1ddbbd0e39c3a30be869563df367bf14ab7df104e4e1760

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
e80b2b3662a9a30eeb07127345ad286552644fa9
Public record ID
record:sha256:909912d5e468a3d4b1ddbbd0e39c3a30be869563df367bf14ab7df104e4e1760

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
909912d5e468a3d4b1ddbbd0e39c3a30be869563df367bf14ab7df104e4e1760
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.