What is CVE-2026-18140?
A vulnerability in the `aws-smithy-json` runtime crate before version 0.62.7 allows uncontrolled recursion in the path that skips unknown JSON keys. This can be exploited by remote unauthenticated users to cause a denial of service (process abort) via stack exhaustion. It is recommended to upgrade to version 0.62.7 or later.
Azərbaycanca: AWS Smithy JSON runtime crate'in 0.62.7-dən əvvəlki versiyalarında aşkar edilən bu zəiflik, emal edilməyən JSON açarlarının (unknown-key skip) sonsuz rekursiyaya səbəb olmasına yol verir. Bu, uzaqdan autentifikasiya olunmamış istifadəçilərə stack tükənməsi yolu ilə xidmətə qarşı Denial of Service (DoS) hücumu təşkil etməyə imkan yaradır. Zəifliyin aradan qaldırılması üçün `aws-smithy-json` crate-ini 0.62.7 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of the AWS Smithy JSON crate are affected by CVE-2026-18140?
This vulnerability affects versions of the `aws-smithy-json` crate before 0.62.7.
What mitigation is recommended for CVE-2026-18140?
It is recommended to upgrade the `aws-smithy-json` crate to version 0.62.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.