Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59884

Опубликовано: 14 июл. 2026
Источник: debian
EPSS Низкий

Описание

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pyasn1fixed0.6.4-1package

Примечания

  • https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j

  • Fixed by: https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 (v0.6.4)

EPSS

Процентиль: 27%
0.00349
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

CVSS3: 5.9
redhat
18 дней назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

CVSS3: 7.5
nvd
18 дней назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

CVSS3: 7.5
msrc
16 дней назад

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

CVSS3: 7.5
github
11 дней назад

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

EPSS

Процентиль: 27%
0.00349
Низкий