CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes

Published 2026-08-20T21:35:57Zd11fd8e2495ff26743157a12c818768e70b7ee5f26bd55953fa02f1ebcfb1267

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
ed870d4dc7aeb25086d51a1b82ede083e7982ffd
Public record ID
record:sha256:d11fd8e2495ff26743157a12c818768e70b7ee5f26bd55953fa02f1ebcfb1267

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
d11fd8e2495ff26743157a12c818768e70b7ee5f26bd55953fa02f1ebcfb1267
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.