aws-smithy-http-server
Code generation for the AWS SDK for Rust, as well as server and generic smithy client generation.
Activity
- Latest release
- 3w ago
- Total releases
- 82
- Cadence
- ~17 days
- Last 12 months
- 14
Reach
- Downloads
- 1.9M
- Stars
- 663
Details
- License
- Apache-2.0
- First release
- Nov 18, 2021
| Version | Released | |
|---|---|---|
0.67.1
patch
|
0.67.1
patch
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.6
patch
|
0.66.6
patch
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.67.0
unknown
|
0.67.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.5
unknown
|
0.66.5
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.4
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.66.4
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.3
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.66.3
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.66.2
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.66.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.66.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.66.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.65.10
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.10
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.9
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.9
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.8
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.8
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.7
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.7
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.6
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.6
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.5
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.5
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.3
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.3
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.2
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.65.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.1
unknown
Dependencies (24)
+ 16 more
Compare changes
|
|
0.65.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.65.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.64.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.64.1
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.64.0
unknown
yanked
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.64.0
unknown
yanked
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.63.5
unknown
yanked
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.63.5
unknown
yanked
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.63.4
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.63.4
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.63.3
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.63.3
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.63.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.63.2
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.63.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.63.1
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.62.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.62.1
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.62.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.62.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.61.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.61.2
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.61.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.61.1
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.60.6
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.6
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
0.60.5
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.5
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
0.60.4
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.4
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
0.60.3
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.3
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
0.60.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.2
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
0.60.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.1
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.61.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.61.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.60.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.60.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.59.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.59.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.58.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.58.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.57.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.57.2
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.57.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.57.1
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.57.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.57.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.56.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.56.1
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.56.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.56.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.55.4
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.55.4
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.55.3
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.55.3
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.55.2
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.55.2
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.55.1
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.55.1
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.55.0
unknown
1 CVE
CVE-2026-16756
GHSA-jvxp-qmx7-gjpx
Jul 24, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
Network
Low
None
None
SummarySmithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service. ImpactMissing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. Impacted versions: aws-smithy-http-server <= 0.66.4 PatchesThis issue has been addressed in aws-smithy-http-server version 0.66.5. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsThere is no workaround besides updating to the patched version. ContactIf you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. Fixed in
0.66.5
References Updated Jul 24, 2026 · Source: OSV.dev |
0.55.0
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|