CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
Ion ยท 2026-09-09
Actions
Technical Details
| Affected Versions | < 1.12.1 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-85786, CVE-2026-75936 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update ion-java to version 1.12.1 to address the incomplete fix for CVE-2026-85786 and protect against potential denial of service attacks.
For Platform Teams
Deploy the latest ion-java version 1.12.1 to incorporate the necessary security fixes and maintain system reliability.
For Executives
Implement the ion-java version 1.12.1 update to mitigate the memory-amplification denial of service vulnerability and ensure system security.
Source
Related Ion Updates
- CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service (2026-09-09)
- CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 (2026-09-09)
- CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java (2026-09-04)
- CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 (2026-09-02)
- CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service (2026-08-20)