Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

CVE-2026-18140: CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path Vulnerability ID: CVE-2026-18140 CVSS Score: 7.5 Published: 2026-10-02 CVE-2026-18140 is a denial-of-service vulnerability in the Amazon

CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

Vulnerability ID: CVE-2026-18140
CVSS Score: 7.5
Published: 2026-10-02

CVE-2026-18140 is a denial-of-service vulnerability in the Amazon aws-smithy-json Rust crate. Under-validation of recursion depth within the unknown-key skipping path allows a remote, unauthenticated attacker to cause stack exhaustion and process aborts by sending deeply nested JSON arrays.

TL;DR

A stack overflow vulnerability in the aws-smithy-json token-skipping function allows unauthenticated remote attackers to crash Smithy-rs generated servers via deeply nested JSON payloads.

⚠️ Exploit Status: POC

Technical Details

  • Vulnerability Type: Uncontrolled Recursion (CWE-674)
  • Impact: Denial of Service (Process Abort)
  • CVSS v3.1 Score: 7.5 (High)
  • EPSS Score: 0.00431 (Percentile: 35.02%)
  • Exploit Status: Proof of Concept Only
  • CISA KEV Status: Not Listed
  • Affected Components: rust-runtime/aws-smithy-json/src/deserialize/token.rs

Affected Systems

  • aws-smithy-json Rust runtime crate
  • smithy-rs framework generated servers
  • aws-smithy-json: >= 0.32.0, <= 0.62.6 (Fixed in: 0.62.7)

Code Analysis

Commit: 8f08820

Convert skip_inner to iterative loop with hard-coded max nesting depth check to prevent stack exhaustion.

Exploit Details

  • GitHub: PR containing regression tests verifying fix behavior on small stacks.

Mitigation Strategies

  • Update the aws-smithy-json dependency in your Cargo lock file to version 0.62.7 or higher.
  • Limit payload sizes at the reverse proxy or Web Application Firewall (WAF) layer.
  • Inspect incoming JSON arrays to block excessive consecutive nesting syntax (such as repeating brackets).

Remediation Steps:

  1. Navigate to the project directory containing your Cargo.toml file.
  2. Run 'cargo update -p aws-smithy-json' to fetch the latest non-vulnerable version.
  3. Verify the Cargo.lock file ensures aws-smithy-json resolves to version 0.62.7 or higher.
  4. Recompile your application using 'cargo build --release' to embed the updated parsing logic.
  5. Deploy the patched executable into production environments.

References

Read the full report for CVE-2026-18140 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.