GHSA-264p-99wq-f4j6

    Dashboard / Vulnerabilities / GHSA-264p-99wq-f4j6

    GHSA-264p-99wq-f4j6

    Published: 3 Jan 2024Last Modified: 10 Sept 2026

    Summary: Ion Java StackOverflow vulnerability

    Details: ### Impact A potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to: * Deserialize Ion text encoded data, or * Deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. Impacted versions: <1.10.5 ### Patches The patch is included in `ion-java` >= 1.10.5. ### Workarounds Do not load data which originated from an untrusted source or that could have been tampered with. **Only load data you trust.** ---- If you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting

    Affected packages

    Package

    Name: com.amazon.ion:ion-java

    Purl: pkg:maven/com.amazon.ion/ion-java

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.10.5

    Affected versions

    1.10.0
    1.10.1
    1.10.2
    1.10.3
    1.10.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-264p-99wq-f4j6 | CVE-DB