PatchSiren cyber security CVE debrief
CVE-2026-84851 Amazon CVE debrief
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. This issue could have significant operational impact, particularly for applications with high availability and security requirements. Defenders should verify usage of affected versions, assess potential impact, and monitor for unusual application behavior. Evidence is based on official CVE Program and NVD sources, with additional references from Amazon and GitHub, but details about the vendor and product are limited, and further verification is needed.
- Vendor
- Amazon
- Product
- ion-c
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-03
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-03
- Advisory updated
- 2026-09-03
Who should care
Developers and administrators using the Amazon Ion-C library, especially in applications with high availability and security requirements, should prioritize assessment and remediation of this vulnerability. This includes reviewing current usage of the library, assessing potential impact, and implementing compensating controls where necessary. Security teams should also monitor for unusual application behavior and verify vendor remediation and update documentation.
Technical summary
The Amazon Ion-C library before version 1.1.6 contains an uncontrolled recursion vulnerability. A remote unauthenticated actor could craft Ion data to exhaust the native call stack, causing the application using the library to crash and resulting in a denial of service. This issue is particularly concerning for applications with high availability and security requirements, as it could lead to significant operational impact.
Defensive priority
High-priority defensive actions are recommended due to the high CVSS score of 8.7 for this vulnerability.
Recommended defensive actions
- Inventory and assess usage of Amazon Ion-C library versions before 1.1.6
- Apply version 1.1.6 or later of the Amazon Ion-C library
- Implement compensating controls such as input validation and rate limiting
- Monitor for unusual application crashes or denials of service
- Verify vendor remediation and update documentation
Evidence notes
Evidence is based on official CVE Program and NVD sources, with additional references from Amazon and GitHub. However, details about the vendor and product are limited, and further verification is needed. The vulnerability affects Amazon Ion-C library versions before 1.1.6, and defenders should verify usage of affected versions, assess potential impact, and monitor for unusual application behavior.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84851 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84851
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84851 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84851
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-094-aws/
ff89ba41-3aa1-4d27-914a-91399e9639e5
-
Source reference
Unverified legacy reference
URL: https://github.com/amazon-ion/ion-c/releases/tag/v1.1.6
ff89ba41-3aa1-4d27-914a-91399e9639e5
-
Source reference
Unverified legacy reference
URL: https://github.com/amazon-ion/ion-c/security/advisories/GHSA-9gfg-hgj4-gh44
ff89ba41-3aa1-4d27-914a-91399e9639e5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.