CVE-2026-85786CWE-409

CVE-2026-85786

High · published September 5, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
26.0
In the wild
Unconfirmed
What it is

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936.

To remediate this issue, users should upgrade to version 1.12.1.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00332 · 26.0th percentile
Weakness
CWE-409 · Improper Handling of Highly Compressed Data (Data Amplification)
Published
2026-09-05T00:17Z
References (2)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 0%
    epss
  • 04 SEP 19:19Z
    Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
    cvelistv5