CVE-2026-104020: Uncontrolled recursion in the Ion reader in Amazon Ion Python
Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.
To remediate this issue, users should upgrade to version 0.15.0 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Ion Pythonto a version that resolves this vulnerability.Fixed in 0.15.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Applications using Amazon Ion Python versions before 0.15.0 are affected if a remote actor can supply Ion values to the application's Ion reader. The described impact is application denial of service through a crash.
What does an attacker need to exploit it?
The attacker does not need authentication or user interaction. They need to send a crafted, deeply nested Ion value to an application that processes it with the vulnerable Ion reader.
What should be done if the application uses a vulnerable version?
Upgrade Amazon Ion Python to version 0.15.0 or later. The provided data does not specify an alternative mitigation when an upgrade cannot be performed immediately.