VDB
CVE-2026-59886
CVE-2026-59886
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 14, 2026
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pyasn1 | pyasn1 | < 0.6.4 |
| chainguard | mlflow | 0, 0, 0 |
| chainguard | spamcheck | 0, 0, 0 |
| chainguard | request-1276 | 0, 0, 0 |
| chainguard | kubeflow-jupyter-web-app | 0, 0, 0 |
| wolfi | kubeflow-jupyter-web-app | 0, 0, 0 |
| chainguard | duplicity | 0, 0, 0 |
| chainguard | label-studio | 0, 0, 0 |
| wolfi | kubeflow-pipelines | 0, 0, 0 |
| chainguard | superset-6.1 | 0, 0, 0 |
| chainguard | metaflow-service-fips | 0, 0, 0 |
| chainguard | awx | 0, 0, 0 |
| wolfi | kubeflow-volumes-web-app | 0, 0, 0 |
| chainguard | wazuh-manager | 0, 0 |
| chainguard | kubeflow-pipelines | 0, 0, 0 |
| chainguard | azureml-inference-server-http-fips | 0, 0, 0 |
| chainguard | authentik-2026.5 | 0, 0, 0 |
| chainguard | mitmproxy | 0, 0, 0 |
| chainguard | kubeflow-pipelines-visualization-server | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0 |
…and 50 more
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 21, 2026 CVE Updated
- Aug 1, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 11, 2026 Distribution Patch
- Aug 11, 2026 Security Advisory
- Aug 19, 2026 Distribution Patch
References
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r x_refsource_CONFIRM
- https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886 x_refsource_MISC
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4 x_refsource_MISC