Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
Vulnerability Description
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations.
Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow remote attackers to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server.
To mitigate this issue, users should upgrade to aws-sdk-rust release-2026-06-02 or later. Users building custom servers with smithy-rs codegen should regenerate from smithy-rs release-2026-06-01 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
aws-sdk-rust 资源管理错误漏洞
Vulnerability Description
AWS aws-sdk-rust是AWS公司开源的一款AWS的软件开发工具包。 aws-sdk-rust release-2026-06-02之前版本存在资源管理错误漏洞,该漏洞源于Amazon smithy-rs代码生成发出的JSON、CBOR和XML反序列化函数中存在不受控制的递归,可能导致远程攻击者通过包含深度嵌套数据的请求造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A