A vulnerability exists in Amazon Ion-C versions prior to 1.1.6 involving uncontrolled recursion. A remote unauthenticated attacker can craft malicious Ion data that triggers excessive recursion, exhausting the native call stack. This results in an application crash and denial of service for any application using the affected library. The issue has been patched in version 1.1.6. AWS has published a security bulletin and a GitHub security advisory addressing the vulnerability. No authentication is required to exploit this issue, increasing the risk exposure for affected deployments.