VYPR

Ion Dotnet

by Amazon Ion

Source repositories

CVEs (2)

  • CVE-2025-11573HigOct 9, 2025
    risk 0.42cvss 7.5epss 0.00

    An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been…

  • CVE-2025-3857HigApr 21, 2025
    risk 0.42cvss 7.5epss 0.01

    When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite…