CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
Ion ยท 2026-09-09
Actions
Technical Details
| Affected Versions | < 1.1.6 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-84851 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update applications using Amazon Ion-C to version 1.1.6 to incorporate the fix for uncontrolled recursion, which sets a default recursion depth limit and raises IERR_STACK_OVERFLOW when exceeded.
For Platform Teams
Adopt the updated Amazon Ion-C version 1.1.6 to enforce a default recursion depth limit, enhancing application stability and security by preventing stack overflows.
For Executives
Implement the upgrade to Amazon Ion-C version 1.1.6 to mitigate the risk of denial of service attacks due to uncontrolled recursion, ensuring application stability and security.
Source
Related Ion Updates
- CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service (2026-09-09)
- CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java (2026-09-09)
- CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java (2026-09-04)
- CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 (2026-09-02)
- CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service (2026-08-20)