---
id: CVE-2026-104020
title: >-
  Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0
  might allow a remote unauthenticated actor to crash the application using the
  library, resulting in a denial of service, via a crafted, deeply nested Ion
  value.

  …
summary: >-
  Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0
  might allow a remote unauthenticated actor to crash the application using the
  library, resulting in a denial of service, via a crafted, deeply nested Ion
  value.

  …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: Amazon
product: ion-python
affected:
  - ion-python < 0.15.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:00.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104020'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-122-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/amazon-ion/ion-python/releases/tag/v0.15.0'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/amazon-ion/ion-python/security/advisories/GHSA-93q6-f8hx-vv7f
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T21:00:32.268Z'
---

## Overview

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.



To remediate this issue, users should upgrade to version 0.15.0 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
