← Back to CVE search

CVE-2026-59884

pyasn1

Description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

CVSS 7.5EPSS 0.349%Risk 0.77
View source
Published
2026-07-14 17:17:14
Affected versions
<0.6.4
Type
Library
Last modified
2026-07-21 14:37:52
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H