Executive brief
Amazon.IonDotnet is a software library used by applications to process Amazon Ion data. A vulnerability in this library allows an attacker to send a specially crafted text file that causes the application to enter an infinite loop. This results in a denial of service, making the affected application unresponsive and potentially disrupting business operations.
Technical details
A denial of service vulnerability exists in Amazon.IonDotnet versions prior to 1.3.2 due to an infinite loop triggered during the processing of Ion data. An attacker can exploit this by providing a specially crafted text input to the library's parser. Successful exploitation leads to high CPU consumption and application unresponsiveness. The issue is resolved in version 1.3.2; however, the library was deprecated as of August 20, 2025, and will not receive further updates beyond this fix.
Affected products
- Amazon IonDotnet < 1.3.2
Timeline
- 2025-08-20: other: Library deprecated
- 2025-10-09: advisory: Bulletin AWS-2025-022 published