PT-2026-58287 · Pypi+3 · Pyasn1+3

CVE-2026-59885

·

Published

2026-07-14

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pyasn1 versions prior to 0.6.4
Description The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A crafted payload containing an OID with many arcs can cause excessive CPU consumption during the decode() call, leading to a denial of service for applications processing untrusted ASN.1 data. Similarly, the encoders exhibit the same quadratic behavior when re-encoding previously decoded attacker-supplied values.
Recommendations Update pyasn1 to version 0.6.4.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92430
CLEANSTART-2026-CR75797
CVE-2026-59885
ECHO-4CAC-D3B9-56BC
GHSA-8PPF-4F7H-5PPJ
OESA-2026-3198
OPENSUSE-SU-2026:11318-1
OPENSUSE-SU-2026:21392-1
PYSEC-2026-3456
RHSA-2026:40236
RHSA-2026:50319
RHSA-2026:50336
SUSE-SU-2026:22765-1
SUSE-SU-2026:22830-1
SUSE-SU-2026:23006-1
SUSE-SU-2026:23167-1
SUSE-SU-2026:3238-1
USN-8712-1

Affected Products

Linuxmint
Red Os
Ubuntu
Pyasn1