CVE-2026-59884

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pyasn1:pyasn1:*:*:*:*:*:python:*:*

History

21 Jul 2026, 14:37

Type Values Removed Values Added
References () https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 - () https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 - Patch
References () https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 - () https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 - Release Notes
References () https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j - () https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j - Third Party Advisory
CPE cpe:2.3:a:pyasn1:pyasn1:*:*:*:*:*:python:*:*
First Time Pyasn1
Pyasn1 pyasn1

14 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 17:17

Updated : 2026-07-21 14:37


NVD link : CVE-2026-59884

Mitre link : CVE-2026-59884

CVE.ORG link : CVE-2026-59884


JSON object : View

Products Affected

pyasn1

  • pyasn1
CWE
CWE-400

Uncontrolled Resource Consumption