Vulnerability Description
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-094-aws/
- https://github.com/amazon-ion/ion-c/releases/tag/v1.1.6
- https://github.com/amazon-ion/ion-c/security/advisories/GHSA-9gfg-hgj4-gh44
FAQ
What is CVE-2026-84851?
CVE-2026-84851 is a vulnerability with a CVSS score of 7.5 (HIGH). An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the appli...
How severe is CVE-2026-84851?
CVE-2026-84851 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84851?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.