Impact
Improper handling of highly compressed Ion documents in Amazon ion-java versions prior to 1.12.1 allows an attacker to craft a compressed payload that, when automatically decompressed, expands to an arbitrarily large size. This results in excessive memory or disk consumption, leading to a denial of service. The weakness is a failure to validate input size and content, classified as CWE‑409.
Affected Systems
The affected product is Amazon ion‑java. All releases before version 1.12.1, including 1.12.0 and older, are vulnerable. Any application or service that consumes Ion data via this library may be impacted.
Risk and Exploitability
The CVSS score of 8.7 signals high severity. EPSS information is not available, so the precise exploitation probability is unknown, but the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker supplies a malicious compressed Ion file to an application that processes Ion data with this library. The exploitation does not require elevated privileges; it merely needs the ability to provide the crafted document to the target service.
OpenCVE Enrichment