← All Advisories

CVE-2026-104020

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-104020

Key Details

CVECVE-2026-104020
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsamazon ion-python
Classified asCWE-674 (Uncontrolled Recursion)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
amazonion-python
SubsystemsGeneral OT
SectorsMultiple

What to Know

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.

To remediate this issue, users should upgrade to version 0.15.0 or later. (NVD)

What to Do

Monitor amazon's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-104020
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-104020