CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. Impacted versions: < 1.1.6 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Improper authentication allows unauthorized access to repositories.
- Who is affected
- Deployments of JFrog Artifactory are affected; specific versions not stated.
- Urgency
- Critical; CISA has confirmed active exploitation in the wild.
- Action
- Apply the latest security patch from JFrog immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Artifactory
Get an email when a new Artifactory advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-094-aws/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-84851 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for - Uncontrolled recursion
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-80783: HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()msrc · 2026-09-08
- highCVE-2026-86145: PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached work…msrc · 2026-09-08
- highCVE-2026-86145: PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached work…nvd · 2026-09-05
- unknownCVE-2026-80783: In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: prevent u…nvd · 2026-09-04
- highCVE-2026-77465: toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Pe…nvd · 2026-09-03
- mediumGHSA-p498-v437-472g: humanfs: Recursive copy follows symlinked files and copies data from outside the source t…ghsa · 2026-09-02
More from AWS Security Bulletins
- unknownCVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards2026-09-08
- unknownCVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs pos…2026-09-04
- unknownCVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server2026-09-04
- unknownCVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java2026-09-04
- unknownCVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver2026-09-04