PT-2026-104008 · Pypi · Amazon Ion Python

·

CVE-2026-104020

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Amazon Ion Python versions prior to 0.15.0
Description Uncontrolled recursion in the Ion reader allows a remote unauthenticated actor to cause a denial of service by crashing the application. This is achieved by providing a crafted, deeply nested Ion value.
Recommendations Upgrade to version 0.15.0 or later.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104020

Affected Products

Amazon Ion Python