CVE-2026-85786 – Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java

​CVE ID :CVE-2026-85786

Published : Sept. 4, 2026, 8:17 p.m. | 50 minutes ago

Description :Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936.

To remediate this issue, users should upgrade to version 1.12.1.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More