Ion Amazon Ion

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazon Ion.

Recent Amazon Ion Security Advisories

Advisory Title Published
2026-07-31 CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool July 31, 2026
2026-07-31 CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin July 31, 2026
2026-07-31 Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react July 31, 2026
2026-07-31 CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers July 31, 2026
2026-07-23 CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() July 23, 2026
2026-07-23 CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service July 23, 2026
2026-07-21 CVE-2026-16317 and CVE-2026-16318: Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols July 21, 2026
2026-07-21 CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes July 21, 2026
2026-07-16 CVE-2026-15895: OS command injection in jsii-diff in AWS jsii July 16, 2026
2026-07-14 CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering July 14, 2026

By the Year

In 2026 there have been 0 vulnerabilities in Amazon Ion. Ion did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 1 7.50

It may take a day or so for new Ion vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon Ion Security Vulnerabilities

Amazon Ion Java Library DoS via IonText Deserialization prior to 1.10.5
CVE-2024-21634 7.5 - High - January 03, 2024

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

Allocation of Resources Without Limits or Throttling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazon Ion or by Amazon? Click the Watch button to subscribe.

Amazon
Vendor

Amazon Ion
Product

subscribe