CVE-2026-23490

EUVD-2026-2865
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
pyasn1pyasn1
𝑥
< 0.6.2
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pyasn1
bookworm
vulnerable
bookworm (security)
0.4.8-3+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
0.4.8-1+deb11u1
fixed
forky
0.6.3-1
fixed
sid
0.6.3-1
fixed
trixie
0.6.1-1+deb13u1
fixed
trixie (security)
0.6.1-1+deb13u2
fixed