Impact
An uncontrolled recursion flaw exists in Amazon Ion‑C’s Ion reader. A remote unauthenticated actor can send crafted Ion data that forces the library to recurse deeply, exhausting the native call stack and causing the application to crash. The resulting denial of service compromises the availability of any system that uses the library. The vulnerability is categorized as CWE‑674.
Affected Systems
Amazon Ion‑C prior to version 1.1.6 is affected. Any product or service that integrates the library without upgrading is at risk until the upgrade to 1.1.6 or newer is applied. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while the EPSS score is not available, the absence of a KEV listing suggests no confirmed exploits yet. The attack requires only the ability to transmit Ion data to an application that uses the library; no authentication is needed. If such data is introduced by an external source, the exceptionally deep recursion can immediately crash the process, leading to a service outage. The vulnerability is therefore reasonably exploitable in typical environments where untrusted Ion data is accepted.
OpenCVE Enrichment