Skip to content
AWSAWS-2026-061

Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows...

UnratedCVE-2026-15957 · Published Jul 21, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-061-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 12:30 PM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-15957 , where uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow a third party to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server. Impacted versions:  aws-sdk-rust crates Resolution: This issue has been addressed in release-2026-06-02 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no workaround beyond updating to the patched versions. References: CVE-2026-15957 GHSA-4f2p-7j38-4xrg Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id"...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-061-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 12:30 PM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-15957 , where uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow a third party to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server. Impacted versions:  aws-sdk-rust crates Resolution: This issue has been addressed in release-2026-06-02 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no workaround beyond updating to the patched versions. References: CVE-2026-15957 GHSA-4f2p-7j38-4xrg Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-061-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes Bulletin ID: 2026-061-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 12:30 PM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-15957 , where uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow a third party to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server. Impacted versions:  aws-sdk-rust crates Resolution: This issue has been addressed in release-2026-06-02 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no workaround beyond updating to the patched versions. References: CVE-2026-15957 GHSA-4f2p-7j38-4xrg Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.", "items": [ { "name": "Learn", "linkURL": "", "items": [ { "heading": "What Is AWS?", "linkURL": "/what-is-aws/?nc1=f_cc

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.