2026-122-AWSHigh
CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-122-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 13:30 PM PDT Description: Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service. Impacted versions: Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.