AWSAWS-2026-067
Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows...
UnratedCVE-2026-18140 · Published Sep 9, 2026
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |
| Sep 10 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | Unrated | No fix yet |
| Sep 10 | Integer overflow in tensor buffer validation in Deep Java Library | Unrated | No fix yet |
| Sep 10 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | Unrated | No fix yet |
| Sep 9 | Issue with awslabs mysql-mcp-server | Unrated | No fix yet |
| Sep 8 | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | Unrated | No fix yet |