


Perceptive Security
SOC/SIEM Consultancy

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the…
Published:
3 september 2026 om 00:00:00
Alert date:
3 september 2026 om 08:01:05
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization
A vulnerability exists in Amazon Ion-C versions prior to 1.1.6 involving uncontrolled recursion. A remote unauthenticated attacker can craft malicious Ion data that causes the native call stack to be exhausted, resulting in application crash and denial of service. The issue requires no authentication to exploit, making it accessible to any remote actor. The vulnerability has been patched in version 1.1.6 of the Ion-C library. AWS has published a security bulletin and the fix is available via the official GitHub release. The flaw is classified as a denial of service vulnerability due to stack exhaustion triggered by specially crafted input data.
Technical details
Mitigation steps:
Affected products:
Amazon Ion-C
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84851
https://aws.amazon.com/security/security-bulletins/2026-094-aws/
https://github.com/amazon-ion/ion-c/releases/tag/v1.1.6
https://github.com/amazon-ion/ion-c/security/advisories/GHSA-9gfg-hgj4-gh44
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
