CVE-2026-59884

Aliases:GHSA-m4p7-r5rc-7g4jPYSEC-2026-3455DEBIAN-CVE-2026-59884UBUNTU-CVE-2026-59884CGA-2ccg-7h57-mhc4CGA-3j36-jq64-j7xpCGA-4m66-89g7-fh2hCGA-4xvg-cmwq-rqjmCGA-684m-2pvh-ghmvCGA-6cq8-qr73-p7q7CGA-798g-qv7h-f85vCGA-8jgj-j9hp-79c4CGA-9h63-5rpq-9fj6CGA-9hf2-39wv-c3m5CGA-9qv7-5fg6-4339CGA-f5fj-94f4-gw9gCGA-g72g-q2pp-crr9CGA-g9cc-54hp-rp4pCGA-jcxc-mpmp-pvf8CGA-mh9x-46c4-834rCGA-25qp-895q-vmjpCGA-2fwf-37f4-ghrwCGA-35xj-wprp-25mhCGA-393g-xfm8-c9q7CGA-3gx6-rfmq-2crpCGA-43j4-c35p-qmqhCGA-4qm2-x95f-pv7pCGA-5gv2-3jjp-gfwvCGA-5j4v-mcq6-3fr4CGA-628g-ww33-cr68CGA-72m9-vx8r-xwjfCGA-7mh6-69hf-x53pCGA-7rp4-78x7-2992CGA-83mj-h9w9-www4CGA-8cp2-37xh-g9rqCGA-92rv-pwhr-5xh9CGA-h5g6-352c-xgg2CGA-hv3j-4f29-m2j6CGA-jcjf-4qmx-pqfmCGA-jf3f-rc3p-r2m9CGA-jhjg-8w4p-9qw9CGA-jmwg-xjj8-vw68CGA-mj2j-xx3v-qvcjCGA-qfh4-q8c3-p775CGA-qvw5-xmj4-vq44CGA-qwcv-93c7-jv2rCGA-r4c2-hvhq-wq4fCGA-r4r4-rmv5-hx24CGA-r52v-v4v3-rmr5CGA-r65q-7w77-rhg6CGA-v6xp-364c-j7v8CGA-vpvw-pfx9-5gh2CGA-vr77-qvw6-vrh2CGA-vwq4-p6w6-hx7fCGA-w469-8mhm-hh94CGA-x949-5jwx-q688CGA-xxww-3jfc-fq8rCGA-298h-45cv-4c38CGA-343j-r7fh-5cp5CGA-c8v9-g945-xm94CGA-h5fg-jcq8-8382CGA-j9gf-5cq4-wxpfCGA-qc3r-95h3-96rhCGA-vvrj-h7qw-fx35CGA-w6pf-ff36-8fxjCGA-xm4c-v64j-cgfg
Analyzed
Published: 14 Jul 2026, 16:41
Last modified:15 Jul 2026, 13:50

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.35% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 16:41
Published
Vulnerability first disclosed
15 Jul 2026, 13:50
Last Modified
Vulnerability information updated

Description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.35% Percentile: 29%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-3

    < 3.3.0-r4

  • chainguardairflow-3-iamguarded-compat

    all

  • chainguardapache-beam-python-3.12-sdk

    < 2.75.0-r1

  • chainguardauthentik-2026.2

    < 2026.2.6-r11

  • chainguardauthentik-fips-2026.2

    < 2026.2.6-r11

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r3

  • chainguarddatadog-agent-7.71-core-integrations

    all

  • chainguarddatadog-agent-7.72-core-integrations

    all

  • chainguarddatadog-agent-7.75-core-integrations

    all

  • chainguarddatadog-agent-fips-7.71-core-integrations

    all

  • chainguarddatadog-agent-fips-7.72-core-integrations

    all

  • chainguarddatahub-ingestion

    < 1.6.0-r5

  • chainguarddbt-bigquery

    < 1.10.3-r6

  • chainguardduplicity

    < 3.1.0-r2

  • chainguardkserve

    < 0.20.0-r7

  • chainguardkserve-localmodel

    < 0.20.0-r7

  • chainguardkserve-storage-controller

    < 0.19.0-r5 | all

  • chainguardkubeflow-pipelines-apiserver

    < 2.17.0-r4 | < 2.17.2-r4

  • chainguardkubeflow-pipelines-metadata-writer-compat

    < 2.17.2-r4

  • chainguardlmcache-cuda-12.8

    < 0.5.3-r0

  • chainguardlocalstack

    < 4.14.0-r20

  • chainguardmlflow

    < 3.15.0-r1 | < 3.16.0-r0

  • chainguardmlflow-iamguarded-compat

    < 3.15.0-r1

  • chainguardopenstack-keystone-2025.1

    < 27.0.1_git20260618-r7

  • chainguardopenstack-keystone-2025.2

    < 28.0.1_git20260618-r7

  • chainguardopenstack-keystone-2026.1

    < 29.0.1_git20260616-r7

  • chainguardpy3-cassandra-medusa

    < 0.29.1-r1

  • chainguardsuperset-6.0

    < 6.0.0-r15

  • chainguardwazuh-manager-framework

    < 4.14.6-r3

  • chainguardwazuh-manager-framework-fips

    < 4.14.7-r1

  • wolfiairflow-3

    < 3.3.0-r4

  • wolfiairflow-3-iamguarded-compat

    all

  • wolfidatadog-agent-7.72-core-integrations

    all

  • wolfidatadog-agent-7.75-core-integrations

    all

  • wolfikserve

    < 0.20.0-r7

  • wolfikserve-localmodel

    < 0.20.0-r7

  • wolfikserve-storage-controller

    < 0.19.0-r5 | all

  • wolfikubeflow-pipelines-apiserver

    < 2.17.0-r4 | < 2.17.2-r4

  • wolfikubeflow-pipelines-metadata-writer-compat

    < 2.17.2-r4

  • wolfimlflow

    < 3.15.0-r1 | < 3.16.0-r0

  • wolfimlflow-iamguarded-compat

    < 3.15.0-r1

  • wolfipy3-cassandra-medusa

    < 0.29.1-r1

  • wolfisuperset-6.0

    < 6.0.0-r15

  • debianpyasn1

    all | all | all | < 0.4.8-3+deb12u3 | < 0.6.1-1+deb13u3 | < 0.6.4-1

  • ubuntupyasn1

    all | all | all | all

  • pyasn1pyasn1

    < 0.6.4

  • PyPIpyasn1

    < 0.6.4

  • PyPIpyssn1

    < 0.6.4

References (10)