High severity7.5OSV Advisory· Published Oct 9, 2025· Updated Apr 15, 2026
CVE-2025-11573
CVE-2025-11573
Description
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input.
To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Amazon.IonDotnetNuGet | < 1.3.2 | 1.3.2 |
Affected products
2- Range: v0.9.0, v0.9.0-beta, v1.0.0, …
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-q5r6-9qwq-g2wjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-11573ghsaADVISORY
- aws.amazon.com/security/security-bulletins/AWS-2025-022ghsaWEB
- github.com/amazon-ion/ion-dotnet/commit/edaff75fe5abbb71e647bed812c608c0c5e2fbabghsaWEB
- github.com/amazon-ion/ion-dotnet/pull/160ghsaWEB
- github.com/amazon-ion/ion-dotnet/releases/tag/v1.3.2nvdWEB
- github.com/amazon-ion/ion-dotnet/security/advisories/GHSA-q5r6-9qwq-g2wjnvdWEB
- aws.amazon.com/security/security-bulletins/AWS-2025-022/nvd
News mentions
0No linked articles in our index yet.