Description
Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.



To remediate this issue, users should upgrade to version 0.15.0 or later.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Amazon Ion Python contains an uncontrolled recursion defect in its Ion reader that can be provoked with a crafted, deeply nested Ion value. The flaw causes the reader to recurse until the stack is exhausted, terminating the host application and producing a denial of service. The weakness is mapped to CWE-674, representing unbounded recursion. A remote, unauthenticated actor can supply the malicious payload to trigger the crash.

Affected Systems

All releases of Amazon Ion Python earlier than version 0.15.0 are vulnerable. Any project that parses Ion data using these older versions of the library is at risk, including developers and organizations that embed the library in web services, data pipelines, or other applications where untrusted Ion documents may be processed.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity. The exploit requires only a crafted Ion payload and does not depend on authentication or elevated privileges, implying a remote attack vector that is straightforward to construct. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog; however, the high CVSS and remote nature of the attack suggest it could be actively targeted against systems that rely on untrusted Ion input.

Generated by OpenCVE AI on October 1, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Amazon Ion Python library to version 0.15.0 or later.
  • Review application code to ensure that only trusted data is parsed with ion-python, and consider implementing application‑level limits on recursion depth or nested structure size while processing Ion documents.
  • Deploy monitoring or logging to detect unexpected termination of processes that use the Ion Python library and configure alerts for crash events.

Generated by OpenCVE AI on October 1, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000


Thu, 01 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.
Title Uncontrolled recursion in the Ion reader in Amazon Ion Python
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-01T21:07:33.567Z

Reserved: 2026-10-01T16:57:41.444Z

Link: CVE-2026-104020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:18.650

Modified: 2026-10-01T22:17:00.720

Link: CVE-2026-104020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:30:14Z

Weaknesses