Amazon.IonDotnet
NuGet2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Amazon.IonDotnetpage 1 of 1
- CVE-2025-11573HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.22025-10-09
vulnerable: 0.9.0-beta ... 1.3.1 (7 versions)
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August…
- CVE-2025-3857HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.12025-04-21
vulnerable: 0.9.0-beta ... 1.3.0 (6 versions)
When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed …
Check whether Amazon.IonDotnet is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Amazon.IonDotnet CVEs against the assets you own.
Start Free Scan →