CVE-2025-12829 Details
Description
An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.1.4.
A vulnerability exists in Amazon Ion-C versions prior to 1.1.4, where an uninitialized stack read could lead to the exposure of sensitive data in memory. This issue allows a threat actor to craft data and serialize it to Ion text, potentially revealing private information through UTF-8 escape sequences.
Users are advised to upgrade to Amazon Ion-C version 1.1.4. It is also recommended to only accept data from trusted sources that have been written using a supported Ion library.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 7, 2025CISA-ADP
Assessed Nov 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/AWS-2025-027/ | AMZN | AdvisoryRemedy |
| https://github.com/amazon-ion/ion-c/releases/tag/v1.1.4 | AMZN | Release NotesVendor |
| https://github.com/amazon-ion/ion-c/security/advisories/GHSA-7mgf-6x73-5h7r | AMZN | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | AMZN |
Affected Products
| Product | Versions |
|---|---|
| Amazon Ion-C | < 1.1.4 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | CVE Modified | AMZN |
| Nov 7, 2025 | New CVE Received | AMZN |
Volerion