CVE-2026-84851
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
- Published Sep 3, 2026
- CVSS 8.7 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 AWS Security Bulletins ·