CVE-2026-18140: CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path
CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path Vulnerability ID: CVE-2026-18140 CVSS Score: 7.5 Published: 2026-10-02 CVE-2026-18140 is a denial-of-service vulnerability in the Amazon
CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path
Vulnerability ID: CVE-2026-18140
CVSS Score: 7.5
Published: 2026-10-02
CVE-2026-18140 is a denial-of-service vulnerability in the Amazon aws-smithy-json Rust crate. Under-validation of recursion depth within the unknown-key skipping path allows a remote, unauthenticated attacker to cause stack exhaustion and process aborts by sending deeply nested JSON arrays.
TL;DR
A stack overflow vulnerability in the aws-smithy-json token-skipping function allows unauthenticated remote attackers to crash Smithy-rs generated servers via deeply nested JSON payloads.
β οΈ Exploit Status: POC
Technical Details
- Vulnerability Type: Uncontrolled Recursion (CWE-674)
- Impact: Denial of Service (Process Abort)
- CVSS v3.1 Score: 7.5 (High)
- EPSS Score: 0.00431 (Percentile: 35.02%)
- Exploit Status: Proof of Concept Only
- CISA KEV Status: Not Listed
- Affected Components: rust-runtime/aws-smithy-json/src/deserialize/token.rs
Affected Systems
- aws-smithy-json Rust runtime crate
- smithy-rs framework generated servers
-
aws-smithy-json: >= 0.32.0, <= 0.62.6 (Fixed in:
0.62.7)
Code Analysis
Commit: 8f08820
Convert skip_inner to iterative loop with hard-coded max nesting depth check to prevent stack exhaustion.
Exploit Details
- GitHub: PR containing regression tests verifying fix behavior on small stacks.
Mitigation Strategies
- Update the aws-smithy-json dependency in your Cargo lock file to version 0.62.7 or higher.
- Limit payload sizes at the reverse proxy or Web Application Firewall (WAF) layer.
- Inspect incoming JSON arrays to block excessive consecutive nesting syntax (such as repeating brackets).
Remediation Steps:
- Navigate to the project directory containing your Cargo.toml file.
- Run 'cargo update -p aws-smithy-json' to fetch the latest non-vulnerable version.
- Verify the Cargo.lock file ensures aws-smithy-json resolves to version 0.62.7 or higher.
- Recompile your application using 'cargo build --release' to embed the updated parsing logic.
- Deploy the patched executable into production environments.
References
- Patch Commit: Convert skip_inner to Iterative Pattern
- GitHub PR #4685: Replace Recursion with Iterative Model
- AWS Security Bulletin 2026-067-aws
- GitHub Security Advisory GHSA-8ffr-xgwf-xj56
- Crates.io Package Release: aws-smithy-json 0.62.7
- NVD - CVE-2026-18140 Detail
- Wiz Vulnerability Database Profile
Read the full report for CVE-2026-18140 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.