Junglewise Threat Intelligence

CVE-2026-59885: pyasn1 algorithmic complexity denial of service in OID processing

CVE-2026-59885 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: pyasn1 (PyPI), Pyasn1. Vendors: PyPI, Pyasn1.

Executive brief

A vulnerability in the pyasn1 library, which is used to handle ASN.1 data for protocols like LDAP, SNMP, and Kerberos, can allow an attacker to crash or slow down an application. By sending a specially crafted small data package, an attacker can force the system to consume excessive CPU resources, leading to a denial of service. This can disrupt critical services that rely on digital certificates or secure network communications.

Technical details

The BER/CER/DER decoders and encoders in pyasn1 (specifically ObjectIdentifierPayloadDecoder, RelativeOIDPayloadDecoder, and their encoder counterparts) process OID values in quadratic time relative to the number of arcs. An attacker can exploit this by providing a crafted ASN.1 payload (tens of kilobytes) containing an OID with a large number of arcs, causing the decode() or encode() calls to consume seconds of CPU time. This algorithmic complexity vulnerability (CWE-407) is not mitigated by previous arc-size limits which only bounded the byte length of individual arcs. The issue is fixed in version 0.6.4 by implementing linear-time arc accumulation.

Affected products

  • pyasn1 pyasn1 <= 0.6.3

Timeline

  • 2026-07-09: disclosed: Vulnerability reported and published to GitHub repository
  • 2026-07-14: advisory: Published to the National Vulnerability Database (NVD)
  • 2026-07-21: advisory: GitHub Advisory GHSA-8ppf-4f7h-5ppj published
  • 2026-07-21: patched: Fixed in version 0.6.4

References

Related threats