Skip to main content

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

Bulletin ID: 2026-122-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 13:30 PM PDT

Description:

Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service.

Impacted versions:  < 0.15.0

Resolution:

This issue has been addressed in Amazon Ion Python version 0.15.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Disable ion-python's C extension (simpleion.c_ext = False) and explicitly handle RecursionError raised from within the simpleion module.

References:

Acknowledgement:

We would like to thank Weiqi Wang and Lucas C. Cordeiro, University of Manchester, for collaborating on this issue through the coordinated vulnerability disclosure process.


Please email aws-security@amazon.com with any security questions or concerns..