VDB
CVE-2026-59884
CVE-2026-59884
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 14, 2026
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pyasn1 | pyasn1 | < 0.6.4 |
| chainguard | kubeflow-pipelines | 0, 0, 0 |
| chainguard | dbt-bigquery | 0, 0, 0 |
| wolfi | kubeflow-pipelines | 0, 0, 0 |
| chainguard | wazuh-manager | 0, 0 |
| wolfi | mlflow | 0, 0, 0 |
| chainguard | authentik-2026.2 | 0, 0, 0 |
| chainguard | superset-6.0 | 0, 0, 0 |
| chainguard | openstack-keystone-2025.1 | 0, 0, 0 |
| chainguard | authentik-fips-2026.5 | 0, 0, 0 |
| chainguard | datahub-ingestion | 0, 0, 0 |
| chainguard | openstack-keystone-2026.1 | 0, 0, 0 |
| wolfi | kserve | 0, 0, 0 |
| wolfi | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| wolfi | superset-6.0 | 0, 0, 0 |
| chainguard | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0 |
| chainguard | mlflow | 0, 0, 0 |
…and 11 more
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Aug 1, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j x_refsource_CONFIRM
- https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 x_refsource_MISC
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 x_refsource_MISC
- https://github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-3455.yaml advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-59884 advisory
- https://github.com/advisories/GHSA-m4p7-r5rc-7g4j advisory