Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

Project Subscriptions

Vendors Products
Jboss Enterprise Application Platform Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0219 Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.
Github GHSA Github GHSA GHSA-264p-99wq-f4j6 Ion Java StackOverflow vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat jboss Enterprise Application Platform
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0
cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform

Tue, 13 Aug 2024 23:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-03T21:53:26.420Z

Reserved: 2023-12-29T03:00:44.955Z

Link: CVE-2024-21634

cve-icon Vulnrichment

Updated: 2025-11-03T21:53:26.420Z

cve-icon NVD

Status : Modified

Published: 2024-01-03T23:15:08.943

Modified: 2025-11-03T22:16:44.847

Link: CVE-2024-21634

cve-icon Redhat

Severity : Important

Publid Date: 2024-01-03T00:00:00Z

Links: CVE-2024-21634 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses