CVE-2026-104020: Amazon Ion-Python

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.

Affected products

  • Amazon Ion-Python: before 0.15.0 (fixed in 0.15.0)

Published 2026-10-01. Last modified 2026-10-02.