High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-59884
CVE-2026-59884
Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyasn1PyPI | < 0.6.4 | 0.6.4 |
Affected products
32- osv-coords30 versionspkg:apk/chainguard/airflow-3pkg:apk/chainguard/apache-beam-python-3.12-sdkpkg:apk/chainguard/authentik-2026.2pkg:apk/chainguard/authentik-fips-2026.2pkg:apk/chainguard/authentik-fips-2026.5pkg:apk/chainguard/datahub-ingestionpkg:apk/chainguard/dbt-bigquerypkg:apk/chainguard/duplicitypkg:apk/chainguard/kserve-storage-controllerpkg:apk/chainguard/kubeflow-pipelines-apiserverpkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/localstackpkg:apk/chainguard/mlflowpkg:apk/chainguard/mlflow-iamguarded-compatpkg:apk/chainguard/openstack-keystone-2025.1pkg:apk/chainguard/openstack-keystone-2025.2pkg:apk/chainguard/openstack-keystone-2026.1pkg:apk/chainguard/py3-cassandra-medusapkg:apk/chainguard/superset-6.0pkg:apk/chainguard/wazuh-manager-frameworkpkg:apk/chainguard/wazuh-manager-framework-fipspkg:apk/wolfi/airflow-3pkg:apk/wolfi/kserve-storage-controllerpkg:apk/wolfi/kubeflow-pipelines-apiserverpkg:apk/wolfi/mlflowpkg:apk/wolfi/mlflow-iamguarded-compatpkg:apk/wolfi/py3-cassandra-medusapkg:apk/wolfi/superset-6.0pkg:rpm/opensuse/python-pyasn1&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-pyasn1&distro=openSUSE%20Tumbleweed
< 3.3.0-r4+ 29 more
- (no CPE)range: < 3.3.0-r4
- (no CPE)range: < 2.75.0-r1
- (no CPE)range: < 2026.2.6-r11
- (no CPE)range: < 2026.2.6-r11
- (no CPE)range: < 2026.5.6-r3
- (no CPE)range: < 1.6.0-r5
- (no CPE)range: < 1.10.3-r6
- (no CPE)range: < 3.1.0-r2
- (no CPE)range: < 0.19.0-r5
- (no CPE)range: < 2.17.0-r4
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 4.14.0-r20
- (no CPE)range: < 3.15.0-r1
- (no CPE)range: < 3.15.0-r1
- (no CPE)range: < 27.0.1_git20260618-r7
- (no CPE)range: < 28.0.1_git20260618-r7
- (no CPE)range: < 29.0.1_git20260616-r7
- (no CPE)range: < 0.29.1-r1
- (no CPE)range: < 6.0.0-r15
- (no CPE)range: < 4.14.6-r3
- (no CPE)range: < 4.14.7-r1
- (no CPE)range: < 3.3.0-r4
- (no CPE)range: < 0.19.0-r5
- (no CPE)range: < 2.17.0-r4
- (no CPE)range: < 3.15.0-r1
- (no CPE)range: < 3.15.0-r1
- (no CPE)range: < 0.29.1-r1
- (no CPE)range: < 6.0.0-r15
- (no CPE)range: < 0.6.1-160000.5.1
- (no CPE)range: < 0.6.4-1.1
Patches
Vulnerability mechanics
References
6- github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5nvdPatchWEB
- github.com/advisories/GHSA-m4p7-r5rc-7g4jghsaADVISORY
- github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4jnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-59884ghsaADVISORY
- github.com/pyasn1/pyasn1/releases/tag/v0.6.4nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-3455.yamlghsaWEB
News mentions
0No linked articles in our index yet.