Uncontrolled Recursion Vulnerability in Amazon Ion-C Library
CVE-2026-84851

8.7HIGH

Key Information:

Vendor

Amazon

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84851?

The Amazon Ion-C library prior to version 1.1.6 is affected by an uncontrolled recursion vulnerability that can be exploited by remote unauthenticated attackers. By crafting specific Ion data, an attacker may exhaust the native call stack, leading to a crash of the applications using this library. This results in a denial of service, making it crucial for users to upgrade to the latest version to mitigate potential risks.

Affected Version(s)

ion-c 0 < 1.1.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.