VDB

CVE-2026-55244

CVE-2026-55244 PUBLISHED CVSS 5 MEDIUM

Reported by GitHub_M · Published September 14, 2026

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), while run() and eval() in asteval/asteval.py catch Exception rather than these non-Exception BaseException subclasses. When an attacker-controlled expression raises one of these classes, on_raise() passes the class to raise_exception(), and the resulting exception bypasses the interpreter's safety handlers and propagates into the calling application. A consuming service that evaluates untrusted expressions can therefore be terminated or have signal and cleanup handling disrupted, causing denial of service. The separately documented read-only open() capability is not part of this vulnerability. This issue is fixed in version 1.0.9.

Risk Scores

CVSS 3.1
5
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
lmfitasteval< 1.0.9
chainguardkeep-fips0, 0, 0
PyPIasteval0
lmfitasteval< 1.0.9, < 1.0.9
chainguardkeep0, 0, 0
wolficheckov0, 0, 0
chainguardcheckov0, 0, 0

Timeline

  • Aug 1, 2026 CVE Published
  • Aug 21, 2026 Security Advisory
  • Sep 10, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›