Amazon Ion Java Amazonion Amazon Ion Java

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazonion Amazon Ion Java.

By the Year

In 2026 there have been 2 vulnerabilities in Amazonion Amazon Ion Java with an average score of 7.5 out of ten.

Year Vulnerabilities Average Score
2026 2 7.50

It may take a day or so for new Amazon Ion Java vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazonion Amazon Ion Java Security Vulnerabilities

DoS via GZIP auto-decompress in Amazon ion-java <1.12.0
CVE-2026-75936 7.5 - High - August 18, 2026

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.

Data Amplification

Amazon ion-java 1.12 Uncontrolled Heap Prealloc via ion stream cursor
CVE-2026-75935 7.5 - High - August 18, 2026

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.

Stack Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazonion Amazon Ion Java or by Amazonion? Click the Watch button to subscribe.

Amazonion
Vendor

subscribe