CVE-2026-85786
Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.33%
- CWE
- CWE-409
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- Amazon ion-java
Weakness type
Related vulnerabilities
- CVE-2026-46387 — Suricata http2: decompression bomb can cause denial of service in Suricata
- CVE-2026-79695 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-69304 — ASP.NET Core Denial of Service Vulnerability
- CVE-2026-82520 — parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
- CVE-2026-84382 — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
- CVE-2026-78594 — Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service
- CVE-2026-72628 — Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
- CVE-2026-82864 — pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb