GHSA-q5r6-9qwq-g2wj · Severity: high · Ecosystem: nuget — Amazon.IonDotnet is vulnerable to Denial of Service attacks
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates.
Conclusion & alert: CVE-2025-11573 is rated Moderate Risk (46/100): CVSS High severity, with low exploitation likelihood (EPSS 0.39%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.39% | +0.34% |
| 2 | 2025-11-10 | 0.04% | 0.05% | +0.01% |
| 3 | 2025-10-10 | — | 0.04% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
GHSA-q5r6-9qwq-g2wj · Severity: high · Ecosystem: nuget — Amazon.IonDotnet is vulnerable to Denial of Service attacks
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||