VYPR

NuGet package

amazon.iondotnet

pkg:nuget/amazon.iondotnet

Vulnerabilities (2)

  • CVE-2025-11573HigOct 9, 2025
    affected < 1.3.2fixed 1.3.2

    An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecat

  • CVE-2025-3857HigApr 21, 2025
    affected < 1.3.1fixed 1.3.1

    When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite l