CVE-2026-30922 is a high-severity Denial of Service (DoS) vulnerability impacting the pyasn1 Python library, specifically versions prior to 0.6.3. An unauthenticated, remote attacker can exploit this by sending crafted ASN.1 data containing deeply nested structures, which triggers uncontrolled recursion in the decoder, leading to a Python interpreter crash or an Out-of-Memory condition. With a CVSSv3.1 score of 7.5 (HIGH), this vulnerability has a low attack complexity and primarily impacts system availability. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB, though remediation efforts have been noted in community discussions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.6.3CPE matchmatch criteria | cpe:2.3:a:pyasn1:pyasn1:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
pyasn1 vulnerabilities
Mar 30, 2026pyasn1 vulnerability
Mar 30, 2026Denial of Service in pyasn1 via Unbounded Recursion
Mar 17, 2026pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
Mar 10, 2026pyasn1 vulnerabilities
pyasn1 vulnerability