PT-2026-58107 · Pypi+4 · Pyasn1+4

CVE-2026-59886

·

Published

2026-07-14

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pyasn1 versions prior to 0.6.4
Description The univ.Real type converts its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value containing a very large exponent can cause float conversion to consume excessive CPU and memory, potentially hanging applications that decode untrusted ASN.1 data. This occurs during operations such as prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call.
Recommendations Update pyasn1 to version 0.6.4.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:53363
ALSA-2026:53364
ALSA-2026:53365
ALSA-2026:59241
ALSA-2026:59242
ALSA-2026:59243
AZL-92436
CLEANSTART-2026-CR75797
CVE-2026-59886
ECHO-E4FD-E77A-5A0F
GHSA-HM4W-WWCW-MR6R
OESA-2026-3198
OPENSUSE-SU-2026:11318-1
OPENSUSE-SU-2026:21392-1
PYSEC-2026-3457
RHSA-2026:50319
RHSA-2026:50336
RHSA-2026:53363
RHSA-2026:53364
RHSA-2026:53365
RHSA-2026:58546
RHSA-2026:58547
RHSA-2026:58548
RHSA-2026:58811
RHSA-2026:58820
RHSA-2026:58821
RHSA-2026:58822
RHSA-2026:58834
RHSA-2026:58835
RHSA-2026:59238
RHSA-2026:59239
RHSA-2026:59240
RHSA-2026:59241
RHSA-2026:59242
RHSA-2026:59243
RHSA-2026:59244
RHSA-2026:59245
RHSA-2026:59246
RHSA-2026:59247
RHSA-2026:59248
RHSA-2026:59329
SUSE-SU-2026:22765-1
SUSE-SU-2026:22830-1
SUSE-SU-2026:23006-1
SUSE-SU-2026:23167-1
SUSE-SU-2026:3238-1
USN-8712-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Pyasn1