aws-smithy-http-server <= 0.66.4 Vulnerable to Slowloris DoS
aws-smithy-http-server versions <= 0.66.4 appear to be vulnerable to unauthenticated Slowloris denial of service due to missing timeouts and connection limits.
What happened
The aws-smithy-http-server crate, when used in versions <= 0.66.4, is under investigation for a potential security issue. The default serve() path in these versions reportedly allocates resources without limits, allowing unauthenticated Slowloris denial of service attacks. This vulnerability, tracked as GHSA-JVXP-QMX7-GJPX, is not yet confirmed but is considered high severity. Engineers using aws-smithy-http-server should assess their exposure by checking if their deployment includes versions <= 0.66.4. It is recommended to upgrade to version 0.66.5 as a precaution. For more details, consult the primary source at https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-jvxp-qmx7-gjpx.
How 0Day mitigates this
aws-smithy-http-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.