Uncontrolled Recursion in Ion Reader Affects Amazon Ion Python Library
CVE-2026-104020
8.7HIGH
What is CVE-2026-104020?
The Ion reader in the Amazon Ion Python library prior to version 0.15.0 is prone to an uncontrolled recursion issue. This vulnerability can be exploited by a remote, unauthenticated actor, allowing them to crash the application through crafted, deeply nested Ion values, leading to a denial of service. To enhance security and prevent potential exploits, users are advised to upgrade to version 0.15.0 or later.
Affected Version(s)
ion-python 0 < 0.15.0
