Vulnerability Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pyasn1 | Pyasn1 | < 0.6.2 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970Patch
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2ProductRelease Notes
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhqVendor Advisory
- https://lists.debian.org/debian-lts-announce/2026/02/msg00002.htmlVendor Advisory
FAQ
What is CVE-2026-23490?
CVE-2026-23490 is a vulnerability with a CVSS score of 7.5 (HIGH). pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. T...
How severe is CVE-2026-23490?
CVE-2026-23490 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23490?
Check the references section above for vendor advisories and patch information. Affected products include: Pyasn1 Pyasn1, Debian Debian Linux.