Amazonion Amazon Ion Java
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Amazonion Amazon Ion Java.
By the Year
In 2026 there have been 2 vulnerabilities in Amazonion Amazon Ion Java with an average score of 7.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 7.50 |
It may take a day or so for new Amazon Ion Java vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Amazonion Amazon Ion Java Security Vulnerabilities
DoS via GZIP auto-decompress in Amazon ion-java <1.12.0
CVE-2026-75936
7.5 - High
- August 18, 2026
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.
Data Amplification
Amazon ion-java 1.12 Uncontrolled Heap Prealloc via ion stream cursor
CVE-2026-75935
7.5 - High
- August 18, 2026
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.
Stack Exhaustion
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Amazonion Amazon Ion Java or by Amazonion? Click the Watch button to subscribe.