PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84851 Amazon CVE debrief

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. This issue could have significant operational impact, particularly for applications with high availability and security requirements. Defenders should verify usage of affected versions, assess potential impact, and monitor for unusual application behavior. Evidence is based on official CVE Program and NVD sources, with additional references from Amazon and GitHub, but details about the vendor and product are limited, and further verification is needed.

Vendor
Amazon
Product
ion-c
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-03
Original CVE updated
2026-09-03
Advisory published
2026-09-03
Advisory updated
2026-09-03

Who should care

Developers and administrators using the Amazon Ion-C library, especially in applications with high availability and security requirements, should prioritize assessment and remediation of this vulnerability. This includes reviewing current usage of the library, assessing potential impact, and implementing compensating controls where necessary. Security teams should also monitor for unusual application behavior and verify vendor remediation and update documentation.

Technical summary

The Amazon Ion-C library before version 1.1.6 contains an uncontrolled recursion vulnerability. A remote unauthenticated actor could craft Ion data to exhaust the native call stack, causing the application using the library to crash and resulting in a denial of service. This issue is particularly concerning for applications with high availability and security requirements, as it could lead to significant operational impact.

Defensive priority

High-priority defensive actions are recommended due to the high CVSS score of 8.7 for this vulnerability.

Recommended defensive actions

  • Inventory and assess usage of Amazon Ion-C library versions before 1.1.6
  • Apply version 1.1.6 or later of the Amazon Ion-C library
  • Implement compensating controls such as input validation and rate limiting
  • Monitor for unusual application crashes or denials of service
  • Verify vendor remediation and update documentation

Evidence notes

Evidence is based on official CVE Program and NVD sources, with additional references from Amazon and GitHub. However, details about the vendor and product are limited, and further verification is needed. The vulnerability affects Amazon Ion-C library versions before 1.1.6, and defenders should verify usage of affected versions, assess potential impact, and monitor for unusual application behavior.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84851 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84851

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84851 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84851

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-094-aws/

    ff89ba41-3aa1-4d27-914a-91399e9639e5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/amazon-ion/ion-c/releases/tag/v1.1.6

    ff89ba41-3aa1-4d27-914a-91399e9639e5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/amazon-ion/ion-c/security/advisories/GHSA-9gfg-hgj4-gh44

    ff89ba41-3aa1-4d27-914a-91399e9639e5

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.