2026-122-AWSHigh

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

Published
October 1, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-122-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 13:30 PM PDT Description: Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service. Impacted versions: Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)