CVE-2026-59885
Last modified
CVE-2026-59885 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pyasn1 | Pyasn1 | < 0.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59885?
How severe is CVE-2026-59885?
How do I fix CVE-2026-59885?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5988A vulnerability was detected in Tenda F451 1.0.0.7. This imp…8.8
- CVE-2026-59880Immutable.js provides many Persistent Immutable data structu…7.5
- CVE-2026-59881AIOHTTP is an asynchronous HTTP client/server framework for …6.9
- CVE-2026-59882guzzlehttp/psr7 is a PSR-7 HTTP message library implementati…6.5
- CVE-2026-59883Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, Co…6.1
- CVE-2026-59884pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4…7.5
- CVE-2026-59886pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4…7.5
- CVE-2026-59887linkify-it is a links recognition library with full Unicode …7.5
- CVE-2026-59888jackson-databind contains the general-purpose data-binding f…6.5
- CVE-2026-59889jackson-databind contains the general-purpose data-binding f…6.5
- CVE-2026-5989A flaw has been found in Tenda F451 1.0.0.7. Affected is the…8.8
- CVE-2026-59890setuptools is a package that allows users to download, build…6.1
Are you affected by CVE-2026-59885?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
