A high-severity vulnerability, identified as CVE-2026-16756 with a CVSS score of 8.7, exists in the default aws-smithy-http-server serve path due to missing connection and header-read timeouts and the absence of a concurrent-connection cap. This flaw allows unauthenticated Slowloris denial of service attacks by remote attackers opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. The vulnerability impacts versions of aws-smithy-http-server up to 0.66.4, potentially leading to significant business disruptions as servers become overwhelmed and unable to process legitimate requests.
We recommend you to update aws-smithy-http-server to version 0.66.5.[/subscribe_to_unlock_form]
A high-severity vulnerability, identified as CVE-2026-16756 with a CVSS score of 8.7, exists in the default aws-smithy-http-server serve path due to missing connection and header-read timeouts and the absence of a concurrent-connection cap. This flaw allows unauthenticated Slowloris denial of service attacks by remote attackers opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. The vulnerability impacts versions of aws-smithy-http-server up to 0.66.4, potentially leading to significant business disruptions as servers become overwhelmed and unable to process legitimate requests.
We recommend you to update aws-smithy-http-server to version 0.66.5.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]