Logo
vulnerabilityCVE-2026-59884
Name
CVE-2026-59884
Source
NVD ( link)Debian ( link)
Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-pyasn1
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
master
0.6.4
Not Affected