Answer in brief
CVE-2026-18140 records a High severity (CVSS 7.5) vulnerability in aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers. The current sources do not mark it as known exploited. The current feed maps aws-smithy-json (crates.io), aws-smithy-json (rust). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps aws-smithy-json (crates.io), aws-smithy-json (rust). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:amazon:aws-smithy-json:*:*:*:*:*:rust:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| aws-smithy-jsoncrates.io | >=0 <0.62.7 | 0.62.7 |
| aws-smithy-jsonrust | <=0.62.6 | 0.62.7 |
Published upstream
Jul 30, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Aug 11, 2026
### Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists which allows uncontrolled recursion in the unknown-key skip path of the Amazon aws-smithy-json runtime crate in versions 0.62.6 and earlier. ### Impact Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. Impacted versions: aws-smithy-json <= 0.62.6 ### Patches This issue has been addressed in aws-smithy-json version 0.62.7. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ### Workarounds There are no workarounds besides updating to the patched version. ### References If you have any questions or comments about this advisory, AWS asks that you contact [AWS/Amazon] Security via their [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.
Quoted source text, attributed separately from HOL analysis.