HIGH7.5
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
- https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
- https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:13553
- https://access.redhat.com/errata/RHSA-2026:14020
- https://access.redhat.com/errata/RHSA-2026:17446
- https://access.redhat.com/errata/RHSA-2026:17595
- https://access.redhat.com/errata/RHSA-2026:17611
- https://access.redhat.com/errata/RHSA-2026:1903
- https://access.redhat.com/errata/RHSA-2026:1904
- https://access.redhat.com/errata/RHSA-2026:1905
- https://access.redhat.com/errata/RHSA-2026:1906
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:2221
- https://access.redhat.com/errata/RHSA-2026:2299
- https://access.redhat.com/errata/RHSA-2026:2300
- https://access.redhat.com/errata/RHSA-2026:2302
- https://access.redhat.com/errata/RHSA-2026:2303
- https://access.redhat.com/errata/RHSA-2026:2309
- https://access.redhat.com/errata/RHSA-2026:24476
- https://access.redhat.com/errata/RHSA-2026:24483
- https://access.redhat.com/errata/RHSA-2026:2453
- https://access.redhat.com/errata/RHSA-2026:2460
- https://access.redhat.com/errata/RHSA-2026:2483
- https://access.redhat.com/errata/RHSA-2026:2486
- https://access.redhat.com/errata/RHSA-2026:24866
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:2712
- https://access.redhat.com/errata/RHSA-2026:2758
- https://access.redhat.com/errata/RHSA-2026:28042
- https://access.redhat.com/errata/RHSA-2026:30088
- https://access.redhat.com/errata/RHSA-2026:3354
- https://access.redhat.com/errata/RHSA-2026:3359
- https://access.redhat.com/errata/RHSA-2026:3958
- https://access.redhat.com/errata/RHSA-2026:3959
- https://access.redhat.com/errata/RHSA-2026:4138
- https://access.redhat.com/errata/RHSA-2026:4139
- https://access.redhat.com/errata/RHSA-2026:4140
- https://access.redhat.com/errata/RHSA-2026:4141
- https://access.redhat.com/errata/RHSA-2026:4142
- https://access.redhat.com/errata/RHSA-2026:4143
- https://access.redhat.com/errata/RHSA-2026:4144
- https://access.redhat.com/errata/RHSA-2026:4145
- https://access.redhat.com/errata/RHSA-2026:4146
- https://access.redhat.com/errata/RHSA-2026:4147
- https://access.redhat.com/errata/RHSA-2026:4148
- https://access.redhat.com/errata/RHSA-2026:4943
- https://access.redhat.com/errata/RHSA-2026:5606
- https://access.redhat.com/security/cve/CVE-2026-23490
- https://bugzilla.redhat.com/show_bug.cgi?id=2430472
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23490.json