Executive brief
smithy-rs is a Rust code generator used by AWS SDK and AWS services to create serialization and deserialization logic for JSON, CBOR, and XML data formats. A flaw in the generated deserializers allows an attacker to send specially crafted messages containing recursive data structures that cause the service to crash or become unresponsive, disrupting availability for legitimate users. This can be exploited without authentication over the network.
Technical details
The vulnerability is an uncontrolled recursion flaw in the smithy-rs code generator's output for JSON, CBOR, and XML deserializers. When processing recursive shape definitions (shapes that reference themselves), the generated deserializers lack proper depth-checking mechanisms to prevent stack exhaustion or runaway resource consumption. An unauthenticated attacker can send network requests with deeply nested payloads matching the recursive shape structure to trigger denial of service. The attack vector is network-based and requires no authentication or user interaction. Services built with vulnerable versions of smithy-rs and exposed to untrusted input are susceptible. AWS has published patches addressing the code generator to emit proper recursion depth checks.
Affected products
- AWS smithy-rs
Timeline
- 2026-09-22: disclosed