To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q5r6-9qwq-g2wj | Amazon.IonDotnet is vulnerable to Denial of Service attacks |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon ion |
|
| Vendors & Products |
Amazon
Amazon ion |
Thu, 09 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 09 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates. | |
| Title | Denial of Service issue in Amazon.IonDotnet | |
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-10-09T19:34:39.743Z
Reserved: 2025-10-09T17:32:12.383Z
Link: CVE-2025-11573
Updated: 2025-10-09T19:34:36.875Z
Status : Awaiting Analysis
Published: 2025-10-09T18:15:49.543
Modified: 2025-10-14T19:37:28.107
Link: CVE-2025-11573
No data.
OpenCVE Enrichment
Updated: 2025-10-10T11:17:41Z
Github GHSA