bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, September 4, 2026

Amazon ion-java Memory Amplification Flaw Needs Your Attention

Amazon ion-java versions below 1.12.1 have a memory-amplification denial of service vulnerability (CVE-2026-85786) triggered by highly compressed data expansion. The previous fix in 1.12.0 didn't fully patch the issue, so you'll need to upgrade immediately if you're using this Java library. This is a real threat—compressed payloads can balloon into massive memory consumption and crash your service.

source: [aws/security-bulletin]