An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
Title Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
First Time appeared Amazon
Amazon ion-c
Weaknesses CWE-674
CPEs cpe:2.3:a:amazon:ion-c:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon ion-c
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-03T13:15:45.459Z

Reserved: 2026-09-02T13:01:03.758Z

Link: CVE-2026-84851

cve-icon Vulnrichment

Updated: 2026-09-03T13:15:42.742Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T05:16:46.640

Modified: 2026-09-03T16:44:01.873

Link: CVE-2026-84851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T09:45:03Z

Weaknesses