Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression.



To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.

Project Subscriptions

Vendors Products
Amazon Ion Subscribe
Amazon Ion Java Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 18 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.
Title Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java
First Time appeared Amazon Ion
Amazon Ion amazon Ion Java
Weaknesses CWE-409
CPEs cpe:2.3:a:amazon_ion:amazon_ion_java:*:*:*:*:*:*:*:*
Vendors & Products Amazon Ion
Amazon Ion amazon Ion Java
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-18T19:52:20.092Z

Reserved: 2026-08-18T15:50:51.183Z

Link: CVE-2026-75936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T20:17:34.317

Modified: 2026-08-18T20:17:34.317

Link: CVE-2026-75936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses