HIGH 8.7 NVD
CVE-2026-84851
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
References
- https://aws.amazon.com/security/security-bulletins/2026-094-aws/
- https://github.com/amazon-ion/ion-c/releases/tag/v1.1.6
- https://github.com/amazon-ion/ion-c/security/advisories/GHSA-9gfg-hgj4-gh44
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-03 via NVD.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.