VYPR

Ion C

by Amazon Ion

Source repositories

CVEs (2)

  • CVE-2026-84851HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.01

    An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.

  • CVE-2025-12829MedNov 7, 2025
    risk 0.33cvss 6.2epss 0.00

    An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should…