CVE-2026-59885

EUVD-2026-43955
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.9%
Affected Products (NVD)
VendorProductVersion
pyasn1pyasn1
𝑥
< 0.6.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pyasn1
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
0.6.4-1
fixed
sid
0.6.4-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pyasn1
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pyasn1-doc
Amazon Linux 2023
0:0.4.8-4.amzn2023.0.5
fixed
python2-pyasn1
Amazon Linux 2
0:0.1.9-7.amzn2.0.5
fixed
python2-pyasn1-modules
Amazon Linux 2
0:0.1.9-7.amzn2.0.5
fixed
python3-pyasn1
Amazon Linux 2
0:0.1.9-7.amzn2.0.5
fixed
Amazon Linux 2023
0:0.4.8-4.amzn2023.0.5
fixed
python3-pyasn1-modules
Amazon Linux 2
0:0.1.9-7.amzn2.0.5
fixed
Amazon Linux 2023
0:0.4.8-4.amzn2023.0.5
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-pyasn1
Azure Linux 3.0
0:0.4.8-3.azl3
fixed