Vulnerability Description
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/AWS-2025-022/
- https://github.com/amazon-ion/ion-dotnet/releases/tag/v1.3.2
- https://github.com/amazon-ion/ion-dotnet/security/advisories/GHSA-q5r6-9qwq-g2wj
FAQ
What is CVE-2025-11573?
CVE-2025-11573 is a vulnerability with a CVSS score of 7.5 (HIGH). An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should ...
How severe is CVE-2025-11573?
CVE-2025-11573 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11573?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.