CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

Ion ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions < 1.1.6
Regions all
CVE IDs CVE-2026-84851
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update applications using Amazon Ion-C to version 1.1.6 to incorporate the fix for uncontrolled recursion, which sets a default recursion depth limit and raises IERR_STACK_OVERFLOW when exceeded.

For Platform Teams

Adopt the updated Amazon Ion-C version 1.1.6 to enforce a default recursion depth limit, enhancing application stability and security by preventing stack overflows.

For Executives

Implement the upgrade to Amazon Ion-C version 1.1.6 to mitigate the risk of denial of service attacks due to uncontrolled recursion, ensuring application stability and security.

Source

View original AWS announcement โ†’

Related Ion Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.