Junglewise Threat Intelligence

CVE-2026-104020: Amazon Ion Python uncontrolled recursion in Ion reader

CVE-2026-104020 · Severity: high · Published 2026-10-01

Technologies: Amazon AWS. Vendors: Amazon.

Executive brief

Amazon Ion Python is a library that parses the Ion data format used in AWS services and applications. A flaw in the Ion reader allows attackers to send specially crafted nested Ion data that triggers unbounded recursion, causing the application to crash and deny service to legitimate users.

Technical details

An uncontrolled recursion vulnerability in the Ion reader component of Amazon Ion Python before 0.15.0 permits deeply nested Ion values to exhaust the call stack. The vulnerability requires the application to parse untrusted Ion data; no authentication is needed. An attacker can exploit this via network to cause a denial of service. A patch is available in version 0.15.0, and as a workaround, users can disable the C extension and explicitly handle RecursionError exceptions.

Affected products

  • Amazon Ion Python before 0.15.0

Timeline

  • 2026-10-01: disclosed

References

Related threats