CVE-2026-23490
pyasn1 has a DoS vulnerability in decoder
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
| CWE | CWE-770 |
| Vendor | pyasn1 |
| Product | pyasn1 |
| Published | Jan 16, 2026 |
| Last Updated | Jun 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for pyasn1 pyasn1
Be the first to know when new high vulnerabilities affecting pyasn1 pyasn1 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
pyasn1 / pyasn1
< 0.6.2
References
github.com: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq github.com: https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970 github.com: https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2 lists.debian.org: https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-23490 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2430472 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23490.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4148 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2758 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3959 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13512 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:28042 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3958 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13508 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17595 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17446 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2309 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4138 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1905 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3354 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1906 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4146 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4145 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2483 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4147 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2486 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4144 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2221 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4139 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2303 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4140 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2300 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4142 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2302 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4143 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2299 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4141 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1903 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:3359 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:1904 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2712 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2453 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2460 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30088 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13553 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13545 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24866 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:5606 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:17611 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24977 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:19712 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:14020 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24476 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:24483 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:4943