A vulnerability exists in Amazon Ion-C versions prior to 1.1.6 involving uncontrolled recursion. A remote unauthenticated attacker can craft malicious Ion data that causes the native call stack to be exhausted, resulting in application crash and denial of service. The issue requires no authentication to exploit, making it accessible to any remote actor. The vulnerability has been patched in version 1.1.6 of the Ion-C library. AWS has published a security bulletin and the fix is available via the official GitHub release. The flaw is classified as a denial of service vulnerability due to stack exhaustion triggered by specially crafted input data.