Executive brief
A vulnerability in the pyasn1 library, which is used to handle data encoded in the ASN.1 format, can allow an attacker to crash an application. By sending a specially crafted data value, an attacker can force the application to consume excessive CPU and memory resources, leading to a denial-of-service. This affects any system that processes and then logs, prints, or compares untrusted ASN.1 data.
Technical details
The pyasn1 library's univ.Real type is vulnerable to uncontrolled resource consumption (CWE-400) during float conversion. The root cause is the use of exact big-integer exponentiation when converting (mantissa, base, exponent) values to Python floats. An attacker can provide a BER/CER/DER-encoded REAL value with a very large exponent, causing the process to hang while attempting to materialize an astronomically large integer. This is triggered by operations such as prettyPrint(), str(), comparisons, or explicit float() calls on decoded objects. The issue is fixed in version 0.6.4 by using math.ldexp() for binary values and implementing overflow checks for decimal values.
Affected products
- pyasn1 pyasn1 <= 0.6.3
Timeline
- 2026-07-09: disclosed: Initial report to GitHub Advisory Database
- 2026-07-14: advisory: NVD publication date
- 2026-07-21: patched: GitHub Advisory reviewed and updated with patch information