CARGO · JULY 2026 · EARLY WARNING

aws-smithy-http-server <= 0.66.4 Vulnerable to Slowloris DoS

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-JVXP-QMX7-GJPXSeverity: HIGH

aws-smithy-http-server versions <= 0.66.4 appear to be vulnerable to unauthenticated Slowloris denial of service due to missing timeouts and connection limits.

What happened

The aws-smithy-http-server crate, when used in versions <= 0.66.4, is under investigation for a potential security issue. The default serve() path in these versions reportedly allocates resources without limits, allowing unauthenticated Slowloris denial of service attacks. This vulnerability, tracked as GHSA-JVXP-QMX7-GJPX, is not yet confirmed but is considered high severity. Engineers using aws-smithy-http-server should assess their exposure by checking if their deployment includes versions <= 0.66.4. It is recommended to upgrade to version 0.66.5 as a precaution. For more details, consult the primary source at https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-jvxp-qmx7-gjpx.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If aws-smithy-http-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats