Amazon Ion-C Vulnerability: Update to 1.1.6 Required
Amazon Ion-C before version 1.1.6 has a nasty uncontrolled recursion bug (CVE-2026-84851) that lets attackers crash your app with specially crafted Ion data. If you're using ion-c in your stack, you need to update immediately—this is a denial-of-service vulnerability affecting all versions below 1.1.6. Remote attackers can exploit this without authentication, so don't sleep on this one.
source: [aws/security-bulletin]