Executive brief
Amazon Ion Python is a library that parses the Ion data format used in AWS services and applications. A flaw in the Ion reader allows attackers to send specially crafted nested Ion data that triggers unbounded recursion, causing the application to crash and deny service to legitimate users.
Technical details
An uncontrolled recursion vulnerability in the Ion reader component of Amazon Ion Python before 0.15.0 permits deeply nested Ion values to exhaust the call stack. The vulnerability requires the application to parse untrusted Ion data; no authentication is needed. An attacker can exploit this via network to cause a denial of service. A patch is available in version 0.15.0, and as a workaround, users can disable the C extension and explicitly handle RecursionError exceptions.
Affected products
- Amazon Ion Python before 0.15.0
Timeline
- 2026-10-01: disclosed