漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
Vulnerability Description
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow remote attackers to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server. To mitigate this issue, users should upgrade to aws-sdk-rust release-2026-06-02 or later. Users building custom servers with smithy-rs codegen should regenerate from smithy-rs release-2026-06-01 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
aws-sdk-rust 资源管理错误漏洞
Vulnerability Description
AWS aws-sdk-rust是AWS公司开源的一款AWS的软件开发工具包。 aws-sdk-rust release-2026-06-02之前版本存在资源管理错误漏洞,该漏洞源于Amazon smithy-rs代码生成发出的JSON、CBOR和XML反序列化函数中存在不受控制的递归,可能导致远程攻击者通过包含深度嵌套数据的请求造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A