CVE-2026-104020: Amazon Ion-Python
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.
Affected products
- Amazon Ion-Python: before 0.15.0 (fixed in 0.15.0)
Published 2026-10-01. Last modified 2026-10-02.