CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
AWS ยท 2026-07-23
Actions
Technical Details
| Affected Versions | <= 0.66.4 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-16756 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the aws-smithy-http-server to version 0.66.5 to address the CVE-2026-16756 vulnerability and prevent potential denial of service attacks.
For Platform Teams
Deploy the latest aws-smithy-http-server version 0.66.5 to enhance the security posture of your platform and protect against unauthenticated denial of service attacks.
For Executives
Implement the upgrade to aws-smithy-http-server version 0.66.5 to mitigate the risk of unauthenticated denial of service attacks, ensuring the security and reliability of your services.