Back to overview

CVE-2026-16756

HIGH
7.5
CVSS 3.1
Description
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.

Metadata

CVE ID
CVE-2026-16756
State
PUBLISHED
Assigner
AMZN
Reserved
2026-07-23 13:10 UTC
Published
2026-07-23 18:32 UTC
Last updated
2026-07-23 19:03 UTC
Primary CWE
CWE-770
CWE-770 Allocation of resources without limits or throttling
Vendor / Product
AWS / aws-smithy-http-server
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
AWS aws-smithy-http-server 0 ≤ 0.66.4
Weakness (CWE)
CWESourceDescription
CWE-770 cna CWE-770 Allocation of resources without limits or throttling
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview