CVE-2026-59884
EUVD-2026-4395614.07.2026, 17:17
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyasn1 | pyasn1 | 𝑥 < 0.6.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| python-pyasn1-doc |
| ||||
| python2-pyasn1 |
| ||||
| python2-pyasn1-modules |
| ||||
| python3-pyasn1 |
| ||||
| python3-pyasn1-modules |
|