Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
UnratedCVE-2026-84851 · Published Sep 2, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. Impacted versions: < 1.1.6 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | Unverified access point ownership in Amazon EFS CSI Driver | Unrated | No fix yet |
| Sep 4 | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server | Unrated | No fix yet |
| Sep 3 | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development... | Unrated | No fix yet |
| Sep 3 | OS command injection in the Amazon CodeCatalyst blueprints SDK | Unrated | No fix yet |
| Sep 1 | Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK | Unrated | No fix yet |
| Aug 31 | OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination | Unrated | No fix yet |