Sceawere

Vulnerability Detail

CVE-2026-104020UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Uncontrolled Recursion Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
Amazon
Product
ion-python
Attack Type
CWE-674 Uncontrolled recursion
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-01T21:17:18.650Z",
  "pubdate": "2026-10-01T21:17:18.650Z",
  "executiveSummary": "The Amazon Ion Python library is susceptible to a denial-of-service (DoS) vulnerability due to uncontrolled recursion within its Ion reader component.\nThis vulnerability stems from the library's inability to adequately limit the recursion depth when parsing Ion-encoded data structures.\nA remote, unauthenticated attacker can exploit this flaw by submitting a maliciously crafted, deeply nested Ion value to an application utilizing the affected library.\nProcessing such a payload causes the underlying Python interpreter to exhaust its call stack, resulting in an immediate process crash.\nThe vulnerability affects versions of Amazon Ion Python prior to 0.15.0.\nGiven that the attack does not require authentication and can be triggered via network-delivered inputs, the risk to availability for services relying on this parser is significant.\nSuccessful exploitation results in an application-level outage, forcing service administrators to manually restart affected processes or services.",
  "technicalDetails": "The vulnerability resides within the recursive descent parser implementation of the Amazon Ion Python reader. When the reader encounters nested Ion containers (such as structs, lists, or s-expressions), it utilizes recursive function calls to traverse the data hierarchy.\nThe root cause is a lack of depth-limiting mechanisms or recursion guards in the parser's logic. By design, recursive parsers allocate stack frames for each level of nesting; without a depth-check, the stack grows linearly with the nesting complexity of the input data.\nAn attacker can exploit this by constructing a malicious Ion stream where the nesting depth exceeds the maximum recursion limit allowed by the Python interpreter. When the victim application invokes the Ion reader to parse this serialized input, the library recursively descends into the structure until a 'RecursionError' is raised.\nBecause this exception is typically unhandled during the reading process, it results in an unhandled exception state that terminates the application process entirely.\nThe attack flow follows a straightforward trajectory: 1) The attacker identifies an input vector where the application parses user-supplied Ion data. 2) The attacker crafts a payload consisting of an excessively nested sequence of containers (e.g., [ [ [ ... ] ] ]). 3) The attacker delivers this payload over the network to the target application. 4) The parser attempts to traverse the structure, consuming stack memory until the Python interpreter triggers a stack overflow-related crash. 5) The application crashes, resulting in a denial-of-service condition for all legitimate users of that service instance.\nThe vulnerability is present in all versions of the Amazon Ion Python library prior to 0.15.0. No special privileges or authentication are required for exploitation, as the vulnerability is triggered during the standard deserialization phase. The impact is limited to availability, as there is no evidence that this recursion flaw provides a vector for arbitrary code execution or data exfiltration; however, it remains a potent tool for disrupting services."
}
CVE-2026-104020: Uncontrolled Recursion Denial of Service (HIGH Severity, CVSS: 7.5) | Sceawere