CVE-2025-12829: Amazon Ion-C
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.1.4.
Affected products
- Amazon Ion-C
Published 2025-11-07. Last modified 2026-10-07.