CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

Bulletin ID: 2026-094-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/02/2026 13:30 PM PDT

Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.

This issue has been addressed in ion-c version 1.1.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fix, which sets a default recursion depth limit. When this limit is exceeded, IERR_STACK_OVERFLOW is raised, allowing the application to handle the error and continue.

Prior to 1.1.6, unbounded recursion can be avoided by discontinuing use of ion-c APIs that automatically re-write the data being read by an ion_reader (ion_writer_write_one_value / ion_writer_write_all_values), replacing this logic with code that manually walks the value tree (either iteratively, or recursively with a manually enforced depth limit). In version 1.1.6, a default recursion depth limit is automatically enforced.

We would like to thank Asadbek Fatullayev for collaborating on this issue through the coordinated vulnerability disclosure process.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-094-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 15, 2026 20:57
Versions
2 recorded
Identity
781df5e041787b2d74bfd2fb1745aeebfceebd2a

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.