Bug 2500380 (CVE-2026-59885) - CVE-2026-59885 pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
Summary: CVE-2026-59885 pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted A...
Keywords:
Status: NEW
Alias: CVE-2026-59885
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 18:17 UTC by OSIDB Bzimport
Modified: 2026-08-25 19:31 UTC (History)
114 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:50319 0 None None None 2026-08-04 17:57:03 UTC
Red Hat Product Errata RHSA-2026:50336 0 None None None 2026-08-04 18:44:31 UTC

Description OSIDB Bzimport 2026-07-14 18:17:35 UTC
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.

Comment 3 errata-xmlrpc 2026-08-04 17:56:53 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:50319 https://access.redhat.com/errata/RHSA-2026:50319

Comment 4 errata-xmlrpc 2026-08-04 18:44:26 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:50336 https://access.redhat.com/errata/RHSA-2026:50336


Note You need to log in before you can comment on or make changes to this bug.