Uncontrolled Recursion in Ion Reader Affects Amazon Ion Python Library
CVE-2026-104020

8.7HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
1 October 2026

What is CVE-2026-104020?

The Ion reader in the Amazon Ion Python library prior to version 0.15.0 is prone to an uncontrolled recursion issue. This vulnerability can be exploited by a remote, unauthenticated actor, allowing them to crash the application through crafted, deeply nested Ion values, leading to a denial of service. To enhance security and prevent potential exploits, users are advised to upgrade to version 0.15.0 or later.

Affected Version(s)

ion-python 0 < 0.15.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

University of Manchester
.