Pyasn1 is a Python library for ASN.1 structure parsing and encoding that, despite its narrow scope, is embedded across a variety of security and network software where ASN.1 data handling is required. The recurring vulnerability signal centers on resource-allocation issues and uncontrolled recursion within the parsing logic, reflecting the complexity and depth-traversal demands of ASN.1 codec implementation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyasn1 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59885HIGH pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the num | Jul 14, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-59886HIGH pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponent | Jul 14, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-59884HIGH pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an | Jul 14, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-30922HIGH pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding | Mar 18, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-23490HIGH pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive co | Jan 16, 2026 | 7.5 | 31 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyasn1.
Media articles that mention a CVE ID that affects a product developed by Pyasn1 — matched by CVE ID, not by vendor name.