VYPR

ion-java

by Amazon

CVEs (3)

  • CVE-2026-75936HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To…

  • CVE-2026-75935HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate…

  • CVE-2026-85786HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP…