Overview
A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker could exploit this by providing a specially crafted payload containing an OID with many arcs, leading to excessive CPU consumption and a denial of service (DoS) in applications that decode untrusted ASN.1 data. The corresponding encoders also exhibit this quadratic behavior when re-encoding attacker-supplied values.
Vendor advisories
- RHSA-2026:50319 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · advisory
- RHSA-2026:50336 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · advisory
- RHSA-2026:59518 · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-25 · advisory
- RHSA-2026:62336 · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · advisory
- RHSA-2026:62335 · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · advisory
- RHSA-2026:40236 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-15 · advisory
- RHSA-2026:56347 · Red Hat · fixed in: Red Hat Migration Toolkit for Applications 8.2 · released 2026-08-18 · advisory
- RHSA-2026:65126 · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · advisory
- RHSA-2026:60520 · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · advisory
- RHSA-2026:53520 · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-08-11 · advisory
- RHSA-2026:52968 · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-08-10 · advisory
- Red Hat VEX · Important · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Migration Toolkit for Virtualization, OpenShift Lightspeed, … · no fix planned: Red Hat Enterprise Linux 6, Migration Toolkit for Virtualization, Red Hat AI Inference Server, Exploit Intelligence, … · updated 2026-09-21 · vex
- RHSA-2026:48933 · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-07-30 · advisory
pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.
Affected:
- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- OpenShift Service Mesh 3
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer
- Service Telemetry Framework 1.5
Fixed:
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat AI Inference Server 3.3
- Red Hat Enterprise Linux AI 3.3
- Red Hat Hardened Images
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9
No fix planned:
- Red Hat Enterprise Linux 6
- Migration Toolkit for Virtualization
- Red Hat AI Inference Server
- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Containers
- OpenShift Service Mesh 3
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Service Telemetry Framework 1.5
Not affected:
- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Enterprise Linux AI 3.3
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
Remediation
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336
For more information visit https://access.redhat.com/errata/RHSA-2026:59518 https://access.redhat.com/errata/RHSA-2026:59518
Workarounds / mitigations:
- Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk.
Package advisory (CVE-2026-59885)
Affected packages:
Patched in:
Source: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5ppj