CVE-2026-59884: PYASN1
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
Affected products
- PYASN1 PYASN1: before 0.6.4 (fixed in 0.6.4)
Published 2026-07-14. Last modified 2026-07-21.