Executive brief
The pyasn1 library, used for encoding and decoding data in protocols like LDAP, SNMP, and Kerberos, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted, deeply nested data structure that causes the software to crash or exhaust all available system memory. This can lead to service outages for any application relying on this library to process network traffic.
Technical details
The pyasn1 library's BER/CER/DER decoder fails to track or limit recursion depth when processing nested ASN.1 structures. Specifically, the 'indefLenValueDecoder', 'valueDecoder', and '_decodeComponentsSchemaless' methods recursively invoke the 'decodeFun' callback for every nested component found. By providing a payload with deeply nested SEQUENCE (0x30) or SET (0x31) tags using Indefinite Length (0x80) markers, a remote, unauthenticated attacker can trigger a RecursionError or a MemoryError (OOM) in the Python interpreter. This vulnerability affects services parsing untrusted ASN.1 data, such as X.509 certificates or LDAP queries. The issue is resolved in version 0.6.3.
Affected products
- pyasn1 pyasn1 <= 0.6.2
Timeline
- 2026-03-17: advisory: GitHub Advisory GHSA-jr27-m4p2-rc6r published
- 2026-03-17: patched: Version 0.6.3 released
- 2026-03-18: disclosed: NVD publication of CVE-2026-30922
References
- https://api.github.com/users/romanticpragmatism
- https://github.com/romanticpragmatism
- https://api.github.com/users/romanticpragmatism/gists%7B/gist_id%7D
- https://api.github.com/users/romanticpragmatism/repos
- https://avatars.githubusercontent.com/u/259386329?v=4
- https://api.github.com/users/romanticpragmatism/events%7B/privacy%7D