PT-2026-58286 · Pypi+3 · Pyasn1+3

CVE-2026-59884

·

Published

2026-07-14

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pyasn1 versions prior to 0.6.4
Description The BER decoder used by CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size. A crafted input can force the construction of an arbitrarily large integer, resulting in CPU cost that grows quadratically and triggering unhandled ValueError exceptions in Python 3.11+ error formatting paths. This affects any application decoding untrusted BER, CER, or DER input.
Recommendations Update to version 0.6.4.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92433
CLEANSTART-2026-CR75797
CVE-2026-59884
ECHO-26AA-F245-5297
GHSA-M4P7-R5RC-7G4J
OESA-2026-3198
OPENSUSE-SU-2026:11318-1
OPENSUSE-SU-2026:21392-1
PYSEC-2026-3455
RHSA-2026:40236
SUSE-SU-2026:22765-1
SUSE-SU-2026:22830-1
SUSE-SU-2026:23006-1
SUSE-SU-2026:23167-1
SUSE-SU-2026:3238-1
USN-8712-1

Affected Products

Linuxmint
Red Os
Ubuntu
Pyasn1