pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
References
| Link | Resource |
|---|---|
| https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 | Patch |
| https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 | Release Notes |
| https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-14 17:17
Updated : 2026-07-21 14:37
NVD link : CVE-2026-59884
Mitre link : CVE-2026-59884
CVE.ORG link : CVE-2026-59884
JSON object : View
Products Affected
pyasn1
- pyasn1
CWE
CWE-400
Uncontrolled Resource Consumption
