{"id":"CVE-2024-21634","aliases":["GHSA-264p-99wq-f4j6"],"url":"https://o3.security/vulnerability/CVE-2024-21634","summary":"Ion Java StackOverflow vulnerability","details":"### Impact\n\nA potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to:\n\n* Deserialize Ion text encoded data, or\n* Deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation.\n\nAn actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library.\n\nImpacted versions: <1.10.5\n\n### Patches\n\nThe patch is included in `ion-java` >= 1.10.5.\n\n### Workarounds\n\nDo not load data which originated from an untrusted source or that could have been tampered with. **Only load data you trust.**\n\n----\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.\n\n[1] https://aws.amazon.com/security/vulnerability-reporting","published":"2024-01-03T22:46:03.585Z","modified":"2026-08-12T03:51:40.616652438Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00827,"percentile":0.555,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.amazon.ion:ion-java","fixedVersion":"1.10.5"},{"ecosystem":"Maven","name":"software.amazon.ion:ion-java","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21634.json"},{"type":"ADVISORY","url":"https://github.com/amazon-ion/ion-java/security/advisories/GHSA-264p-99wq-f4j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21634"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241108-0002/"},{"type":"PACKAGE","url":"https://github.com/amazon-ion/ion-java"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20241108-0002"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.616652438Z"}}