Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/com.amazon.ion/ion-java

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-75935 is a high-severity vulnerability in the Amazon Ion Java library, affecting versions prior to 1.12.0. It involves memory allocation with an excessive size value, leading to a denial of service condition through memory amplification. This vulnerability allows an attacker to cause a denial of service by triggering large memory preallocation based on declared lengths in data processing.

Join the discussion

CVE-2026-75936 is a high-severity vulnerability in Amazon Ion Java before version 1.12.0. It involves improper handling of highly compressed data in the GZIP auto-decompression handler, which can lead to a denial of service when processing crafted compressed Ion documents that expand to very large sizes upon decompression. The issue can be mitigated by upgrading to version 1.12.0 and configuring the parser to disable GZIP decompression or limit buffer size when handling untrusted input.

Join the discussion

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:maven/com.amazon.ion/ion-java
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses