PT-2026-3301 · Pypi+3 · Pyasn1+3

Tsigouris007

·

Published

2026-01-01

·

Updated

2026-03-30

·

CVE-2026-23490

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pyasn1 versions prior to 0.6.2
Description pyasn1, a generic ASN.1 library for Python, contains a denial-of-service issue. The issue stems from incorrect handling of malformed RELATIVE-OIDs with excessive continuation octets during decoding. An attacker can exploit this by providing a crafted input that causes the library to consume excessive memory, potentially leading to a denial of service. The vulnerability is triggered by the decode function when processing maliciously crafted ASN.1 data. The issue can affect systems utilizing pyasn1 for tasks such as LDAP servers, TLS/SSL endpoints, and OCSP responders. A proof-of-concept demonstrates the ability to exhaust memory by sending a payload with numerous continuation octets.
Recommendations Update pyasn1 to version 0.6.2 or later.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2026:1903
ALSA-2026:1904
ALSA-2026:1905
ALSA-2026:1906
ALSA-2026:3354
ALSA-2026:3359
ALSA-2026:4146
CVE-2026-23490
ECHO-8E45-690D-3026
GHSA-63VM-454H-VHHQ
MGASA-2026-0020
OESA-2026-1259
OESA-2026-1260
OESA-2026-1261
OESA-2026-1262
OPENSUSE-SU-2026:10078-1
OPENSUSE-SU-2026:20089-1
RHSA-2026:1903
RHSA-2026:1904
RHSA-2026:1905
RHSA-2026:1906
RHSA-2026:2221
RHSA-2026:2299
RHSA-2026:2300
RHSA-2026:2302
RHSA-2026:2303
RHSA-2026:2309
RHSA-2026:2453
RHSA-2026:2460
RHSA-2026:2483
RHSA-2026:2486
RHSA-2026:2712
RHSA-2026:2758
RHSA-2026:3354
RHSA-2026:3359
RHSA-2026:3958
RHSA-2026:3959
RHSA-2026:4138
RHSA-2026:4139
RHSA-2026:4140
RHSA-2026:4141
RHSA-2026:4142
RHSA-2026:4143
RHSA-2026:4144
RHSA-2026:4145
RHSA-2026:4146
RHSA-2026:4147
RHSA-2026:4148
SUSE-SU-2026:0252-1
SUSE-SU-2026:0300-1
SUSE-SU-2026:0430-1
SUSE-SU-2026:20133-1
SUSE-SU-2026:20158-1
SUSE-SU-2026:20447-1
SUSE-SU-2026:20482-1
USN-7975-1
USN-8134-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Pyasn1