What is CVE-2026-16756?
Missing connection and header-read timeouts, along with the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server, may allow remote attackers to cause a denial of service by opening many connections and sending partial requests. Users should apply configuration changes to enforce these limits and update the server software.
Azərbaycanca: Amazon aws-smithy-http-server-in default serve() yolunda əlaqə və header-oxuma timeouts-larının, həmçinin eyni vaxtda əlaqə limitinin olmaması uzaqdan hücum edənlərə çoxlu əlaqə açıb heç vaxt tamamlanmayan qismən sorğular göndərərək resursları tükətməyə imkan verir. Bu, denial of service vəziyyətinə səbəb ola bilər. İstifadəçilər müvafiq konfiqurasiya dəyişiklikləri ilə bu limitləri tətbiq etməli və server proqramını yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which function of Amazon aws-smithy-http-server was the CVE-2026-16756 vulnerability found?
This flaw is in the default serve() path, related to missing connection and header-read timeouts, as well as the absence of a concurrent-connection cap.
What can an attacker achieve by exploiting CVE-2026-16756?
Remote attackers may cause a denial of service (DoS) by opening many connections and sending partial requests that never complete.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.