What is CVE-2026-15957?
CVE-2026-15957 is an uncontrolled recursion vulnerability in the JSON, CBOR, and XML deserializer functions emitted by the Smithy-RS framework, affecting services using the AWS SDK for Rust. Users should update to the latest patched version of the Smithy-RS library.
Azərbaycanca: CVE-2026-15957, Smithy-RS framework-in JSON, CBOR və XML deserializer funksiyalarında idarə olunmayan rekursiya zəifliyidir. Bu, AWS SDK for Rust istifadə edən xidmətlərə təsir göstərə bilər. İstifadəçilər Smithy-RS kitabxanasını ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: shared vendor: Amazon
FAQ2
During what operation does CVE-2026-15957 occur?
This vulnerability occurs during uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by the Smithy-RS framework.
What measure should be taken to protect against CVE-2026-15957?
Users should update to the latest patched version of the Smithy-RS library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.