Threat Advisory

AWS Smithy-RS Flaw Allows Unauthenticated Slowloris Denial of Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, identified as CVE-2026-16756 with a CVSS score of 8.7, exists in the default aws-smithy-http-server serve path due to missing connection and header-read timeouts and the absence of a concurrent-connection cap. This flaw allows unauthenticated Slowloris denial of service attacks by remote attackers opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. The vulnerability impacts versions of aws-smithy-http-server up to 0.66.4, potentially leading to significant business disruptions as servers become overwhelmed and unable to process legitimate requests.

RECOMMENDATION:

We recommend you to update aws-smithy-http-server to version 0.66.5.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, identified as CVE-2026-16756 with a CVSS score of 8.7, exists in the default aws-smithy-http-server serve path due to missing connection and header-read timeouts and the absence of a concurrent-connection cap. This flaw allows unauthenticated Slowloris denial of service attacks by remote attackers opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. The vulnerability impacts versions of aws-smithy-http-server up to 0.66.4, potentially leading to significant business disruptions as servers become overwhelmed and unable to process legitimate requests.

RECOMMENDATION:

We recommend you to update aws-smithy-http-server to version 0.66.5.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu