SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85786

HIGH · CVSS 7.5 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the ion-java library in Java, where improper handling of highly compressed data can lead to denial of service attacks through specially crafted Ion documents that expand excessively during decompression. This issue arises from insufficient implementation of the GZIP auto-decompression opt-out feature. Organizations using affected versions should prioritize upgrading to version 1.12.1 to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85786
Severity
HIGH
CVSS
7.5
EPSS
0.33%
Java

Original NVD Description

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.