Junglewise Threat Intelligence

CVE-2025-11573: Amazon.IonDotnet is vulnerable to Denial of Service attacks

CVE-2025-11573 · Severity: high · CVSS 4 · Published 2025-10-09

Technologies: Amazon AWS. Vendors: Amazon, NuGet.

Executive brief

Amazon.IonDotnet is a software library used by applications to process Amazon Ion data. A vulnerability in this library allows an attacker to send a specially crafted text file that causes the application to enter an infinite loop. This results in a denial of service, making the affected application unresponsive and potentially disrupting business operations.

Technical details

A denial of service vulnerability exists in Amazon.IonDotnet versions prior to 1.3.2 due to an infinite loop triggered during the processing of Ion data. An attacker can exploit this by providing a specially crafted text input to the library's parser. Successful exploitation leads to high CPU consumption and application unresponsiveness. The issue is resolved in version 1.3.2; however, the library was deprecated as of August 20, 2025, and will not receive further updates beyond this fix.

Affected products

  • Amazon IonDotnet < 1.3.2

Timeline

  • 2025-08-20: other: Library deprecated
  • 2025-10-09: advisory: Bulletin AWS-2025-022 published

References

Related threats