Issue with Amazon ion-java - Memory-amplification denial of service
UnratedCVE-2026-75935 · Published Aug 18, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
- Also known as
- CVE-2026-75936
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 21 | Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards | Unrated | No fix yet |
| Aug 21 | Issue with Athena Federated Query Neptune Connector | Unrated | No fix yet |
| Aug 21 | Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236... | Unrated | No fix yet |
| Aug 20 | Issue with Athena Federated Query Clickhouse Connector | Unrated | No fix yet |
| Aug 18 | Uncontrolled resource consumption in OpenSearch Dashboards capabilities route | Unrated | No fix yet |
| Aug 13 | OpenSearch SQL Plugin - Async Query Validation Bypass | Unrated | No fix yet |