← Terug naar overzicht

A denial of service vulnerability exists in Amazon ion-java before version 1.12.1 due to improper handling of highly compressed data. Remote attackers can exploit this by sending a crafted compressed Ion document that expands to an arbitrarily large size upon GZIP decompression. The flaw stems from insufficient coverage of the GZIP auto-decompression opt-out mechanism that was originally introduced to address CVE-2026-75936. This is a zip bomb-style attack vector that can exhaust system resources. The vulnerability is classified as a DoS risk and affects all versions of ion-java prior to 1.12.1. Users are advised to upgrade to version 1.12.1 to remediate the issue. The fix is available via the official GitHub release and documented in an AWS security bulletin.

Affected products

  • Amazon ion-java

Related CVE's

  • CVE-2026-75936
  • CVE-2026-85786

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Supply Chain & Dependencies