{"id":"CVE-2026-104020","title":"Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.\n…","summary":"Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.\n…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-674"],"vendor":"Amazon","product":"ion-python","affected":["ion-python < 0.15.0"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T22:17:00.720","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104020","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-122-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/amazon-ion/ion-python/releases/tag/v0.15.0","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/amazon-ion/ion-python/security/advisories/GHSA-93q6-f8hx-vv7f","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T21:00:32.268Z","slug":"CVE-2026-104020","body":"## Overview\n\nUncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.\n\n\n\nTo remediate this issue, users should upgrade to version 0.15.0 or later.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}