---
id: CVE-2026-30922
title: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
summary: >-
  pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1`
  library is vulnerable to a Denial of Service (DoS) attack caused by
  uncontrolled recursion when decoding ASN.1 data with deeply nested structures.
  An attacker can…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-674
  - CWE-835
vendor: pyasn1
product: pyasn1
affected:
  - pyasn1 < 0.6.3
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-18T20:16:18.738732Z'
exploitAvailable: true
published: '2026-03-18'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:04:35.736Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-30922'
references:
  - url: 'https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r'
    label: 'https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r'
  - url: >-
      https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0
    label: >-
      https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-30922'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2448553'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-30922'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30922'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24761'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13512'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24762'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13508'
  - url: 'https://access.redhat.com/errata/RHSA-2026:17083'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13916'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19138'
  - url: 'https://access.redhat.com/errata/RHSA-2026:12176'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22135'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22134'
  - url: 'https://access.redhat.com/errata/RHSA-2026:20588'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22987'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22970'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13917'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19355'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13902'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22133'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22132'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22131'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16009'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13553'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13545'
  - url: 'http://www.openwall.com/lists/oss-security/2026/03/20/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2026/05/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:10184'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14020'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17611'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19712'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41928'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6309'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6568'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6720'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6912'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6926'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8437'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://github.com/pyasn1/pyasn1/commit/5a49bd1fe93b5b866a1210f6bf0a3924f21572c8
  - url: 'https://github.com/pyasn1/pyasn1'
  - url: 'https://github.com/pyasn1/pyasn1/releases/tag/v0.6.3'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-2263.yaml
  - url: 'https://github.com/advisories/GHSA-jr27-m4p2-rc6r'
tags:
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - nvd
  - osv
  - pip
  - ghsa
epss: 0.00931
epssPercentile: 0.58957
aliases:
  - GHSA-jr27-m4p2-rc6r
  - PYSEC-2026-2263
ecosystem: pip
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_6
  - enterprise_linux_appstream_tus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_highavailability_v_8
  - enterprise_linux_high_availability_aus_v_8_4
  - enterprise_linux_highavailability_eus_extension_v_8_4
  - enterprise_linux_high_availability_e4s_v_8_6
  - enterprise_linux_high_availability_tus_v_8_6
  - enterprise_linux_high_availability_e4s_v_8_8
  - enterprise_linux_high_availability_tus_v_8_8
  - enterprise_linux_high_availability_e4s_v_9_2
  - enterprise_linux_high_availability_e4s_v_9_4
  - ai_inference_server 3.3
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - enterprise_linux_ai 3.3
  - migration_toolkit 1.8
  - openshift_ai 2.25
  - openshift_ai 3.3
  - openstack 1.5
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
  - trusted_artifact_signer 1.4
ingestedAt: '2026-07-13T18:58:00.060Z'
---

## Overview

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

## Affected

- `pyasn1 < 0.6.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-30922)

Affected packages:

- `pyasn1 < 0.6.3`

Patched in:

- `pyasn1 0.6.3`

Source: https://osv.dev/vulnerability/GHSA-jr27-m4p2-rc6r

## Vendor advisories

- **RHSA-2026:24761** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24761)
- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)
- **RHSA-2026:24762** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24762)
- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)
- **RHSA-2026:17083** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:17083)
- **RHSA-2026:13916** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:13916)
- **RHSA-2026:19138** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19138)
- **RHSA-2026:12176** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8) · released 2026-04-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:12176)
- **RHSA-2026:22135** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4), Red Hat Enterprise Linux High Availability AUS (v.8.4), Red Hat Enterprise Linux HighAvailability EUS EXTENSION (v.8.4) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22135)
- **RHSA-2026:22134** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6), Red Hat Enterprise Linux High Availability E4S (v.8.6), Red Hat Enterprise Linux High Availability TUS (v.8.6) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22134)
- **RHSA-2026:20588** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux High Availability E4S (v.8.8), Red Hat Enterprise Linux High Availability TUS (v.8.8) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20588)
- **Red Hat VEX** · Important · affected: Migration Toolkit for Containers, Migration Toolkit for Virtualization, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), … · no fix planned: Migration Toolkit for Containers, Migration Toolkit for Virtualization, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json)
