CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java

Ion ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions < 1.12.1
Regions all
CVE IDs CVE-2026-85786, CVE-2026-75936
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update ion-java to version 1.12.1 to address the incomplete fix for CVE-2026-85786 and protect against potential denial of service attacks.

For Platform Teams

Deploy the latest ion-java version 1.12.1 to incorporate the necessary security fixes and maintain system reliability.

For Executives

Implement the ion-java version 1.12.1 update to mitigate the memory-amplification denial of service vulnerability and ensure system security.

Source

View original AWS announcement โ†’

Related Ion Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.