CVE-2026-75935 HIGH

CVE-2026-75935: Memory-amplification denial of service via declared-length preallocation in Amazon ion-java

Vendor Amazon Ion
Product Amazon Ion Java
Weakness CWE-789
Published August 18, 2026
Last update August 18, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.

Key dates

02Disclosure timeline

August 18, 2026 CVE published
August 18, 2026 Record updated