CVE-2026-75935: Amazon Ion Java

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.

Affected products

  • Amazon Ion Amazon Ion Java: from 1.9.0, before 1.12.0 (fixed in 1.12.0)

Published 2026-08-18. Last modified 2026-08-20.