VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026

CVE-2026-59884

CVE-2026-59884

Description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pyasn1PyPI
< 0.6.40.6.4

Affected products

32

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.