Denial of Service via Infinite Loop in Amazon.IonDotNet <1.3.2
CVE-2025-11573 Published on October 9, 2025
Denial of Service issue in Amazon.IonDotnet
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input.
To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.
Vulnerability Analysis
CVE-2025-11573 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
Products Associated with CVE-2025-11573
Want to know whenever a new CVE is published for Amazon Aws? stack.watch will email you.
Affected Versions
Amazon.IonDotnet:- Before 1.3.2 is affected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2025-11573
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| nuget | Amazon.IonDotnet | < 1.3.2 | 1.3.2 |
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.