Impact
Amazon Ion Python contains an uncontrolled recursion defect in its Ion reader that can be provoked with a crafted, deeply nested Ion value. The flaw causes the reader to recurse until the stack is exhausted, terminating the host application and producing a denial of service. The weakness is mapped to CWE-674, representing unbounded recursion. A remote, unauthenticated actor can supply the malicious payload to trigger the crash.
Affected Systems
All releases of Amazon Ion Python earlier than version 0.15.0 are vulnerable. Any project that parses Ion data using these older versions of the library is at risk, including developers and organizations that embed the library in web services, data pipelines, or other applications where untrusted Ion documents may be processed.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity. The exploit requires only a crafted Ion payload and does not depend on authentication or elevated privileges, implying a remote attack vector that is straightforward to construct. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog; however, the high CVSS and remote nature of the attack suggest it could be actively targeted against systems that rely on untrusted Ion input.
OpenCVE Enrichment