VDB
CVE-2026-59885
CVE-2026-59885
PUBLISHED
CVSS 7.5 HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
EPSS 0.33% · 26.0th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.33%
26.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | kubeflow-volumes-web-app | 0, 0, 0 |
| chainguard | request-1276 | 0, 0, 0 |
| wolfi | superset-6.0 | 0, 0, 0 |
| chainguard | py3-cassandra-medusa | 0, 0, 0 |
| PyPI | pyasn1 | 0 |
| chainguard | datahub-ingestion-fips | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| chainguard | openstack-keystone-2025.2 | 0, 0, 0 |
| wolfi | kubeflow-pipelines-visualization-server | 0, 0, 0 |
| wolfi | superset-5.0 | 0, 0 |
| chainguard | openstack-keystone-2026.1 | 0, 0, 0 |
| chainguard | spamcheck | 0, 0, 0 |
| chainguard | kubeflow-jupyter-web-app | 0, 0, 0 |
| chainguard | openstack-keystone-2026.1-fips | 0, 0, 0 |
| chainguard | gitlab-cng-19.1 | 0, 0, 0 |
| wolfi | kserve | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| wolfi | datadog-agent-7.73 | 0, 0, 0 |
| chainguard | datadog-agent-fips-7.73 | 0, 0, 0 |
| chainguard | superset-6.1 | 0, 0, 0 |
…and 50 more
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 21, 2026 CVE Updated
- Aug 1, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-59885 advisory
- https://github.com/advisories/GHSA-8ppf-4f7h-5ppj advisory
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj url
- https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9 patch
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 url