{"id":"GHSA-264p-99wq-f4j6","summary":"Ion Java StackOverflow vulnerability","details":"### Impact\n\nA potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to:\n\n* Deserialize Ion text encoded data, or\n* Deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation.\n\nAn actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library.\n\nImpacted versions: \u003c1.10.5\n\n### Patches\n\nThe patch is included in `ion-java` \u003e= 1.10.5.\n\n### Workarounds\n\nDo not load data which originated from an untrusted source or that could have been tampered with. **Only load data you trust.**\n\n----\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n[1] https://aws.amazon.com/security/vulnerability-reporting","aliases":["CVE-2024-21634"],"modified":"2026-09-10T03:50:09.258018779Z","published":"2024-01-03T22:04:08Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-03T22:04:08Z","nvd_published_at":"2024-01-03T23:15:08Z","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/amazon-ion/ion-java/security/advisories/GHSA-264p-99wq-f4j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21634"},{"type":"PACKAGE","url":"https://github.com/amazon-ion/ion-java"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241108-0002"}],"affected":[{"package":{"name":"com.amazon.ion:ion-java","ecosystem":"Maven","purl":"pkg:maven/com.amazon.ion/ion-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.5"}]}],"versions":["1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.4.0","1.5.0","1.5.1","1.6.0","1.6.1","1.7.0","1.7.1","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-264p-99wq-f4j6/GHSA-264p-99wq-f4j6.json"}},{"package":{"name":"software.amazon.ion:ion-java","ecosystem":"Maven","purl":"pkg:maven/software.amazon.ion/ion-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.2.0","1.3.0","1.3.1","1.4.0","1.5.0","1.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-264p-99wq-f4j6/GHSA-264p-99wq-f4j6.json","last_known_affected_version_range":"\u003c 1.10.5"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}