Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

Amazon Ion Python is a software library that helps applications read and write data in the Amazon Ion format. A security issue was found where maliciously crafted data with deep nested structures can cause the Ion reader to crash or raise errors. This leads to the application being unable to function properly, a condition known as denial of service. To address this, users should upgrade to Amazon Ion Python version 0.15.0 or later, which includes a fix. Alternatively, users can disable a specific C extension to help mitigate the problem.

QCS published 4/10/2026, 9:20:15 pm ISTVendor disclosure 2/10/2026, 2:20:19 am ISTVerified 4/10/2026, 9:20:15 pm ISTRevision 1

In plain language

What this advisory means

Amazon Ion Python is a software library that helps applications read and write data in the Amazon Ion format. A security issue was found where maliciously crafted data with deep nested structures can cause the Ion reader to crash or raise errors. This leads to the application being unable to function properly, a condition known as denial of service. To address this, users should upgrade to Amazon Ion Python version 0.15.0 or later, which includes a fix. Alternatively, users can disable a specific C extension to help mitigate the problem.

Technical explanation

How the issue affects the environment

CVE-2026-104020 is a vulnerability in the Ion reader component of Amazon Ion Python before version 0.15.0. The issue is caused by uncontrolled recursion triggered by parsing a crafted, deeply nested Ion value. This excessive recursion leads to Python runtime errors or crashes, causing a denial of service on the application processing the data. The vulnerability can be mitigated by upgrading to version 0.15.0 where the issue is addressed, or by disabling the C extension (simpleion.c_ext = False) and handling Python's RecursionError explicitly in code using the simpleion module.

Operational impact

Why teams should care

Applications that use Amazon Ion Python to process untrusted Ion data are at risk of denial of service due to crashes from malicious inputs. This can cause application downtime, affect service availability, and disrupt business operations relying on systems that ingest Ion-formatted data. Prompt remediation reduces the risk of service disruption and potential reputational damage.

Immediate action

Upgrade to Amazon Ion Python version 0.15.0 or later, which addresses this uncontrolled recursion issue. Ensure any forks or derivative code also incorporates this fix.

Affected and fixed releases

Affected versionsVersions before 0.15.0
Fixed versionsVersion 0.15.0

Temporary risk reduction

Disable the Amazon Ion Python C extension by setting simpleion.c_ext = False, and explicitly catch and handle RecursionError exceptions raised by the simpleion module during Ion data processing.

Evidence and validation checklist

  • AWS Security Bulletins advisory published on 2026-10-01
  • Identification of CVE-2026-104020 describing uncontrolled recursion causing denial of service
  • Recommendation to upgrade to version 0.15.0 to address the issue
  • Workaround instructions to disable C extension and handle RecursionError
  • Acknowledgement credits to researchers involved in vulnerability discovery

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source