In plain language
What this advisory means
Amazon Ion Python is a software library that helps applications read and write data in the Amazon Ion format. A security issue was found where maliciously crafted data with deep nested structures can cause the Ion reader to crash or raise errors. This leads to the application being unable to function properly, a condition known as denial of service. To address this, users should upgrade to Amazon Ion Python version 0.15.0 or later, which includes a fix. Alternatively, users can disable a specific C extension to help mitigate the problem.
Technical explanation
How the issue affects the environment
CVE-2026-104020 is a vulnerability in the Ion reader component of Amazon Ion Python before version 0.15.0. The issue is caused by uncontrolled recursion triggered by parsing a crafted, deeply nested Ion value. This excessive recursion leads to Python runtime errors or crashes, causing a denial of service on the application processing the data. The vulnerability can be mitigated by upgrading to version 0.15.0 where the issue is addressed, or by disabling the C extension (simpleion.c_ext = False) and handling Python's RecursionError explicitly in code using the simpleion module.
Operational impact
Why teams should care
Applications that use Amazon Ion Python to process untrusted Ion data are at risk of denial of service due to crashes from malicious inputs. This can cause application downtime, affect service availability, and disrupt business operations relying on systems that ingest Ion-formatted data. Prompt remediation reduces the risk of service disruption and potential reputational damage.
Immediate action
Upgrade to Amazon Ion Python version 0.15.0 or later, which addresses this uncontrolled recursion issue. Ensure any forks or derivative code also incorporates this fix.
Affected and fixed releases
Temporary risk reduction
Disable the Amazon Ion Python C extension by setting simpleion.c_ext = False, and explicitly catch and handle RecursionError exceptions raised by the simpleion module during Ion data processing.
Evidence and validation checklist
- AWS Security Bulletins advisory published on 2026-10-01
- Identification of CVE-2026-104020 describing uncontrolled recursion causing denial of service
- Recommendation to upgrade to version 0.15.0 to address the issue
- Workaround instructions to disable C extension and handle RecursionError
- Acknowledgement credits to researchers involved in vulnerability discovery
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
