Denial of Service via Infinite Loop in Amazon.IonDotNet <1.3.2
CVE-2025-11573 Published on October 9, 2025

Denial of Service issue in Amazon.IonDotnet
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.

Github Repository Vendor Advisory NVD

Vulnerability Analysis

CVE-2025-11573 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.


Products Associated with CVE-2025-11573

Want to know whenever a new CVE is published for Amazon Aws? stack.watch will email you.

 

Affected Versions

Amazon.IonDotnet:

Vulnerable Packages

The following package name and versions may be associated with CVE-2025-11573

Package Manager Vulnerable Package Versions Fixed In
nuget Amazon.IonDotnet < 1.3.2 1.3.2

Exploit Probability

EPSS
0.14%
Percentile
34.26%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.