{"id":"CVE-2026-59884","aliases":["GHSA-m4p7-r5rc-7g4j","PYSEC-2026-3455"],"title":"pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs","summary":"pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"pyasn1","product":"pyasn1","ecosystem":"pip","affected":["pyasn1 < 0.6.4"],"patched":["pyasn1 0.6.4"],"published":"2026-07-21","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:52.562707948Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m4p7-r5rc-7g4j","references":[{"url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59884"},{"url":"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5"},{"url":"https://github.com/pyasn1/pyasn1"},{"url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-3455.yaml"},{"url":"https://github.com/advisories/GHSA-m4p7-r5rc-7g4j"}],"tags":["osv","pip","ghsa"],"epss":0.00349,"epssPercentile":0.28538,"cwe":["CWE-400"],"ingestedAt":"2026-07-21T19:53:40.133Z","slug":"CVE-2026-59884","body":"## Overview\n\n### Impact\nThe BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled `ValueError` (integer string conversion limit) while the decoder formats error messages, violating the documented `PyAsn1Error` contract and potentially bypassing caller error handling.\n\nAny application decoding untrusted BER/CER/DER input is affected.\n\n### Affected components\n- `pyasn1.codec.ber.decoder` — `decode()` and `StreamingDecoder`\n- `pyasn1.codec.cer.decoder` and `pyasn1.codec.der.decoder`, which inherit\n  the same tag parsing\n- `pyasn1.type.tag` — `Tag`/`TagSet` reprs could raise `ValueError` when\n  rendering oversized tag IDs (reachable through decoder error paths)\n\nThe encoders and the `pyasn1.codec.native` codec are not affected.\n\n### Patches\nFixed in 0.6.4. Long-form tag IDs are now limited to 20 octets (140-bit tag IDs, matching the existing OID arc limit); oversized tags are rejected with `PyAsn1Error`. Tag ID rendering in reprs and error messages was additionally hardened against the interpreter's integer-to-string conversion limit.\n\n### Workarounds\nBound the size of untrusted input passed to `decode()` before calling it.\n\n## Affected packages\n\n- `pyasn1 < 0.6.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyasn1 0.6.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}