Uncontrolled Recursion in aws-smithy-json: A Deep Dive into CVE-2026-18140
This educational analysis delves into CVE-2026-18140, a critical vulnerability in the aws-smithy-json crate that allows for unauthenticated remote denial of service in smithy-rs generated servers. The vulnerability is caused by uncontrolled recursion in the unknown-key skip path, which can be exploited via a single small HTTP request containing deeply nested JSON.