pyasn1 vulnerabilities
CVEs whose affected-version data names the pyasn1 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-59884High· 7.5pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
▾ Twilightpyasn1 · pyasn1EPSS 0.35%via OSV
CVE-2026-30922High· 7.5PoCpyasn1 Vulnerable to Denial of Service via Unbounded Recursion
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can…
▾ Midnightpyasn1 · pyasn1EPSS 0.80%via CVEORG
CVE-2026-23490High· 7.5PoCpyasn1 is a generic ASN.1 library for Python
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
▾ Midnightpyasn1 · pyasn1EPSS 0.77%via NVD