CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-18140

CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 3, 2026·6 min read·4 visits

Executive Summary (TL;DR)

A stack overflow vulnerability in the aws-smithy-json token-skipping function allows unauthenticated remote attackers to crash Smithy-rs generated servers via deeply nested JSON payloads.

CVE-2026-18140 is a denial-of-service vulnerability in the Amazon aws-smithy-json Rust crate. Under-validation of recursion depth within the unknown-key skipping path allows a remote, unauthenticated attacker to cause stack exhaustion and process aborts by sending deeply nested JSON arrays.

Vulnerability Overview

The aws-smithy-json crate is a foundational component of smithy-rs, a framework used to automatically generate HTTP client and server runtimes in Rust from Smithy service models. This package implements low-level parsing routines for parsing structured JSON requests and responses. It exposes a direct attack surface to unauthenticated endpoints that consume JSON.

The vulnerability exists in the mechanisms used to deserialize payloads. When a Smithy-rs generated server processes incoming JSON, it relies on a token-based parsing loop. When encountering fields or keys not declared in the static Smithy interface definition, the parser invokes a utility path named skip_inner to skip past the unmapped elements and continue processing known fields.

The skipping implementation utilized a recursive parsing pattern to process nested arrays or object elements within the unrecognized keys. Because the implementation lacked nested limits, parsing complex structured data could cause uncontrolled recursion, identified as CWE-674. This design flaw allows remote attackers to exhaust the target program's stack allocation, forcing immediate crash states.

Root Cause Analysis

The root cause of CVE-2026-18140 resides in the recursive structure of the skip_inner helper in rust-runtime/aws-smithy-json/src/deserialize/token.rs. In standard execution, when the token stream yields Token::StartObject or Token::StartArray, the function recursively executes skip_inner with an incremented depth tracker. This behavior relies on recursive stack allocation to preserve state across elements of nested structures.

Each nested level in a JSON construct requires a distinct stack frame. A stack frame stores register states, function arguments, local variables, and the return address. When parsing structured input with deep arrays, the nesting structure forces the runtime to allocate stack frames proportional to the layout depth, creating an $O(N)$ stack dependency.

Unlike heap-allocated memory, thread stack limits are strictly bounded. On standard Linux environments, thread stacks range from 2MB to 8MB, and can be smaller in embedded systems or hyper-optimized microservices. When a payload exceeds the maximum stack size, a stack overflow occurs. In Rust, stack overflows bypass standard panic recovery blocks and immediately trigger a SIGSEGV signal, forcing the operating system to abort the server process.

Code Analysis & Fix Verification

The vulnerable implementation recursively executed skip_inner(depth + 1, tokens)? whenever it encountered start tokens for arrays or objects. Below is a code comparison showing how the patch resolved this pattern by converting the logic into an iterative loop that maintains a flat $O(1)$ stack space utilization.

// PRE-PATCH VULNERABLE RECURSION
fn skip_inner<'a>(
    depth: isize,
    tokens: &mut impl Iterator<Item = Result<Token<'a>, Error>>,
) -> Result<(), Error> {
    loop {
        match tokens.next().transpose()? {
            Some(Token::StartObject { .. }) | Some(Token::StartArray { .. }) => {
                // Recursing deepens stack consumption
                skip_inner(depth + 1, tokens)?;
                if depth == 0 { break; }
            }
            Some(Token::EndObject { .. }) | Some(Token::EndArray { .. }) => { break; }
            _ => {}
        }
    }
    Ok(())
}

The remediation replaced the recursive logic with an iterative model tracking current depth in a single mutable variable within one execution frame. It introduces a fixed ceiling limit defined by MAX_SKIP_DEPTH to preemptively discard deeply nested objects before consuming excessive CPU cycles.

// POST-PATCH ITERATIVE FIX
const MAX_SKIP_DEPTH: usize = 512;
 
fn skip_inner<'a>(
    initial_depth: usize,
    tokens: &mut impl Iterator<Item = Result<Token<'a>, Error>>,
) -> Result<(), Error> {
    let mut depth = initial_depth;
    loop {
        match tokens.next().transpose()? {
            Some(Token::StartObject { .. }) | Some(Token::StartArray { .. }) => {
                // Stack use remains flat while depth tracking is updated
                depth = depth.checked_add(1).ok_or_else(|| {
                    Error::custom("exceeded max recursion depth")
                })?;
                if depth > MAX_SKIP_DEPTH {
                    return Err(Error::custom("exceeded max recursion depth"));
                }
            }
            Some(Token::EndObject { .. }) | Some(Token::EndArray { .. }) => {
                debug_assert!(depth > 0);
                depth = depth.saturating_sub(1);
                if depth == 0 { break; }
            }
            None => return Err(Error::custom("expected value")),
            _ => {}
        }
    }
    Ok(())
}

This structural shift removes recursive execution altogether. By limiting parsing recursion to 512 levels, the memory footprint remains constrained, preventing any possibility of memory-exhaustion crashes regardless of incoming structure depth.

Exploitation & Attack Mechanics

Exploitation of CVE-2026-18140 requires no authentication credentials or complex system preconditions. An attacker must locate any public-facing HTTP endpoint managed by a Smithy-rs service that accepts JSON request payloads. Because the deserializer processes payload formatting prior to mapping fields to application handlers, the exploit payload is evaluated as soon as parsing begins.

The attacker formats a JSON request containing an arbitrary, unmapped parameter key. The value mapped to this unrecognized key is structured as an extremely deep recursive array or object string, such as a sequence of nested brackets. This specific configuration forces the parsing engine to select the skip_inner logical branch.

{
  "non_existent_key": [[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[...]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
}

When the deserializer parses this key, it processes each opening bracket. Under vulnerable builds, each bracket initiates a new stack frame, causing the stack pointer to overrun the guard page. The host operating system intercepts the invalid memory write, issues a SIGSEGV signal, and instantly terminates the service process.

Impact Assessment

The impact of exploiting CVE-2026-18140 is a complete denial of service across the targeted system. Because a stack overflow causes the entire operating system process to terminate instantly, active connection streams are forcefully closed without returning a standard error response. This bypasses typical internal recovery mechanics, ensuring that all client tasks on that host thread abort simultaneously.

The vulnerability presents zero threat of unauthorized privilege elevation, arbitrary memory manipulation, or sensitive data disclosure. The core threat vector centers on availability disruption. In multi-tenant environments or single-process architectures, a single malicious HTTP request can disrupt operations for all legitimate users connected to the host.

Due to the low complexity of constructing a payload and the lack of authentication requirements, the vulnerability presents a significant exploitation surface. This risk is reflected in the CVSS v3.1 score of 7.5, reflecting a network-exploitable, low-complexity denial-of-service vector.

Remediation & Mitigation

Remediation of this vulnerability is achieved by upgrading the aws-smithy-json dependency to version 0.62.7 or newer. This update can be applied directly in Cargo environments by executing standard package upgrade procedures, which replaces the vulnerable recursive implementation with the corrected iterative logic.

If immediate recompilation and deployment are not viable, operational workarounds can minimize the exposure profile. Administrators should deploy Web Application Firewall (WAF) rule sets to analyze payload structures and block requests containing abnormally deep arrays or excessive sequential open-bracket sequences.

Additionally, configuring maximum request size thresholds at the reverse proxy or API gateway layers reduces risks. Restricting payloads to a low maximum threshold (e.g., under 100 KB) physically limits the quantity of open-bracket tokens that an attacker can insert into a payload, rendering stack exhaustion attacks impossible.

Official Patches

AWSOfficial patch fixing stack exhaustion in JSON parsing

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Probability
0.43%
Top 65% most exploited

Affected Systems

aws-smithy-json Rust runtime cratesmithy-rs framework generated servers

Affected Versions Detail

Product
Affected Versions
Fixed Version
aws-smithy-json
Amazon
>= 0.32.0, <= 0.62.60.62.7
AttributeDetail
Vulnerability TypeUncontrolled Recursion (CWE-674)
ImpactDenial of Service (Process Abort)
CVSS v3.1 Score7.5 (High)
EPSS Score0.00431 (Percentile: 35.02%)
Exploit StatusProof of Concept Only
CISA KEV StatusNot Listed
Affected Componentsrust-runtime/aws-smithy-json/src/deserialize/token.rs

MITRE ATT&CK Mapping

T1499Endpoint Denial of Service
Impact
CWE-674
Uncontrolled Recursion

The software contains a function that can call itself recursively without a mechanism to limit the recursion depth, leading to excessive stack consumption.

Known Exploits & Detection

GitHubPR containing regression tests verifying fix behavior on small stacks.

Vulnerability Timeline

Patch authored by Russell Cohen via PR #4685
2026-06-01
CVE-2026-18140 published
2026-07-30
AWS publishes security bulletin 2026-067-aws
2026-07-30
NVD updates metadata and base CVSS score
2026-08-10

References & Sources

  • [1]Patch Commit: Convert skip_inner to Iterative Pattern
  • [2]GitHub PR #4685: Replace Recursion with Iterative Model
  • [3]AWS Security Bulletin 2026-067-aws
  • [4]GitHub Security Advisory GHSA-8ffr-xgwf-xj56
  • [5]Crates.io Package Release: aws-smithy-json 0.62.7
  • [6]NVD - CVE-2026-18140 Detail
  • [7]Wiz Vulnerability Database Profile

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•GHSA-FJ2X-MQQP-3V2W
7.5

GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

A sensitive information disclosure vulnerability exists in the Trigger.dev Command Line Interface (CLI) framework. When executing build processes inside CLI v3 packages, the framework's debug deployment logs print unredacted, resolved environment variables and secrets to standard output or log streams. This exposure occurs when the CLI is operated with a high logging verbosity level, enabling any individual or automated system with read access to build logs, CI/CD output consoles, or local development streams to capture plaintext sensitive parameters, such as database credentials, API keys, and private external integration tokens.

Alon Barad
Alon Barad
4 views•6 min read
•about 3 hours ago•CVE-2026-104855
2.0

CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

CVE-2026-104855 is a critical vulnerability involving a race condition and reentrant state desynchronization within Wasmtime, a standalone WebAssembly runtime. Due to incremental mid-operation preemption points in compiler-generated loops for bulk memory and table operations, a host-defined epoch or fuel deadline callback could mutate the WebAssembly Store. Upon resuming, the virtual machine utilized stale cached pointers, resulting in use-after-free, out-of-bounds writes, and sandbox escape.

Amit Schendel
Amit Schendel
3 views•7 min read
•about 4 hours ago•CVE-2026-74802
8.2

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).

Alon Barad
Alon Barad
4 views•5 min read
•about 5 hours ago•CVE-2026-74904
8.7

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 6 hours ago•CVE-2026-71416
8.8

CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 7 hours ago•GHSA-CJCG-CXMH-9WCR
7.5

GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

A critical vulnerability exists in the praxis-proxy library where the omission of default limits on HTTP/2 server options allows remote attackers to trigger a Denial of Service (DoS) using an HPACK compression bomb and flow-control window stalls. This vulnerability is cataloged as GHSA-cjcg-cxmh-9wcr.

Amit Schendel
Amit Schendel
5 views•7 min read