CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service

Ion ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions < 1.12.0
Regions all
CVE IDs CVE-2026-75935, CVE-2026-75936
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update ion-java to version 1.12.0, configure a limited maximum buffer size, and disable automatic GZIP decompression for untrusted input to address critical security vulnerabilities (CVE-2026-75935 and CVE-2026-75936).

For Platform Teams

Deploy the updated ion-java version 1.12.0 across all relevant services to eliminate security risks associated with memory-amplification denial of service vulnerabilities (CVE-2026-75935 and CVE-2026-75936).

For Executives

Implement the latest ion-java version 1.12.0 to mitigate memory-amplification denial of service vulnerabilities (CVE-2026-75935 and CVE-2026-75936) and ensure system security and stability.

Source

View original AWS announcement โ†’

Related Ion Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.