CVE-2026-16756

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
Configurations

No configuration.

History

23 Jul 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 19:16

Updated : 2026-07-23 20:17


NVD link : CVE-2026-16756

Mitre link : CVE-2026-16756

CVE.ORG link : CVE-2026-16756


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling