CVE-2026-59884
Vulnerability Summary
Timeline
Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.35%• Percentile: 29%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- chainguard•airflow-2
all
- chainguard•airflow-3
< 3.3.0-r4
- chainguard•airflow-3-iamguarded-compat
all
- chainguard•apache-beam-python-3.12-sdk
< 2.75.0-r1
- chainguard•authentik-2026.2
< 2026.2.6-r11
- chainguard•authentik-fips-2026.2
< 2026.2.6-r11
- chainguard•authentik-fips-2026.5
< 2026.5.6-r3
- chainguard•datadog-agent-7.71-core-integrations
all
- chainguard•datadog-agent-7.72-core-integrations
all
- chainguard•datadog-agent-7.75-core-integrations
all
- chainguard•datadog-agent-fips-7.71-core-integrations
all
- chainguard•datadog-agent-fips-7.72-core-integrations
all
- chainguard•datahub-ingestion
< 1.6.0-r5
- chainguard•dbt-bigquery
< 1.10.3-r6
- chainguard•duplicity
< 3.1.0-r2
- chainguard•kserve
< 0.20.0-r7
- chainguard•kserve-localmodel
< 0.20.0-r7
- chainguard•kserve-storage-controller
< 0.19.0-r5 | all
- chainguard•kubeflow-pipelines-apiserver
< 2.17.0-r4 | < 2.17.2-r4
- chainguard•kubeflow-pipelines-metadata-writer-compat
< 2.17.2-r4
- chainguard•lmcache-cuda-12.8
< 0.5.3-r0
- chainguard•localstack
< 4.14.0-r20
- chainguard•mlflow
< 3.15.0-r1 | < 3.16.0-r0
- chainguard•mlflow-iamguarded-compat
< 3.15.0-r1
- chainguard•openstack-keystone-2025.1
< 27.0.1_git20260618-r7
- chainguard•openstack-keystone-2025.2
< 28.0.1_git20260618-r7
- chainguard•openstack-keystone-2026.1
< 29.0.1_git20260616-r7
- chainguard•py3-cassandra-medusa
< 0.29.1-r1
- chainguard•superset-6.0
< 6.0.0-r15
- chainguard•wazuh-manager-framework
< 4.14.6-r3
- chainguard•wazuh-manager-framework-fips
< 4.14.7-r1
- wolfi•airflow-3
< 3.3.0-r4
- wolfi•airflow-3-iamguarded-compat
all
- wolfi•datadog-agent-7.72-core-integrations
all
- wolfi•datadog-agent-7.75-core-integrations
all
- wolfi•kserve
< 0.20.0-r7
- wolfi•kserve-localmodel
< 0.20.0-r7
- wolfi•kserve-storage-controller
< 0.19.0-r5 | all
- wolfi•kubeflow-pipelines-apiserver
< 2.17.0-r4 | < 2.17.2-r4
- wolfi•kubeflow-pipelines-metadata-writer-compat
< 2.17.2-r4
- wolfi•mlflow
< 3.15.0-r1 | < 3.16.0-r0
- wolfi•mlflow-iamguarded-compat
< 3.15.0-r1
- wolfi•py3-cassandra-medusa
< 0.29.1-r1
- wolfi•superset-6.0
< 6.0.0-r15
- debian•pyasn1
all | all | all | < 0.4.8-3+deb12u3 | < 0.6.1-1+deb13u3 | < 0.6.4-1
- ubuntu•pyasn1
all | all | all | all
- pyasn1•pyasn1
< 0.6.4
- PyPI•pyasn1
< 0.6.4
- PyPI•pyssn1
< 0.6.4
References (10)
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
- https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4
- https://nvd.nist.gov/vuln/detail/CVE-2026-59884
- https://github.com/pyasn1/pyasn1
- https://github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-3455.yaml
- https://security-tracker.debian.org/tracker/CVE-2026-59884
- https://ubuntu.com/security/CVE-2026-59884
- https://www.cve.org/CVERecord?id=CVE-2026-59884
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59884.json