Severity
7.5HIGH
EPSS
0.0%
top 94.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMar 30

Description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

PyPIpyasn10.6.10.6.2
CVEListV5pyasn1/pyasn1< 0.6.3+1
NVDpyasn1/pyasn1< 0.6.2
Debianpyasn1< 0.4.8-1+deb11u1+3
Ubuntupyasn1< 0.1.7-1ubuntu2.1+esm1+3

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

5
OSV
pyasn1 vulnerabilities2026-03-30
GHSA
pyasn1 has a DoS vulnerability in decoder2026-01-16
OSV
CVE-2026-23490: pyasn1 is a generic ASN2026-01-16
OSV
pyasn1 has a DoS vulnerability in decoder2026-01-16
CVEList
pyasn1 has a DoS vulnerability in decoder2026-01-16

📋Vendor Advisories

5
Ubuntu
pyasn1 vulnerabilities2026-03-30
Red Hat
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion2026-03-18
Ubuntu
pyasn1 vulnerability2026-01-22
Red Hat
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID2026-01-16
Debian
CVE-2026-23490: pyasn1 - pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Servic...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23490 Impact, Exploitability, and Mitigation Steps | Wiz