๐Ÿ” CVE Alert

CVE-2026-23490

HIGH 7.5

pyasn1 has a DoS vulnerability in decoder

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

CWE CWE-770
Vendor pyasn1
Product pyasn1
Published Jan 16, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for pyasn1 pyasn1

Be the first to know when new high vulnerabilities affecting pyasn1 pyasn1 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

pyasn1 / pyasn1
< 0.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq github.com: https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970 github.com: https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2 lists.debian.org: https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-23490 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2430472 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23490.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4148 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2758 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3959 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13512 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:28042 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3958 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13508 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17595 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17446 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2309 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4138 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1905 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3354 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1906 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4146 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4145 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2483 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4147 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2486 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4144 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2221 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4139 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2303 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4140 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2300 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4142 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2302 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4143 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2299 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4141 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1903 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3359 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1904 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2712 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2453 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2460 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30088 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13553 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13545 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24866 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:5606 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17611 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24977 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19712 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:14020 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24476 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24483 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4943