{"schema_version":"1.7.5","id":"GHSA-m4p7-r5rc-7g4j","published":"2026-07-21T19:10:11Z","modified":"2026-08-02T02:59:55.269509518Z","aliases":["CVE-2026-59884","PYSEC-2026-3455"],"related":["CGA-5h6w-88ff-g48p"],"summary":"pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs","details":"### Impact\nThe BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled `ValueError` (integer string conversion limit) while the decoder formats error messages, violating the documented `PyAsn1Error` contract and potentially bypassing caller error handling.\n\nAny application decoding untrusted BER/CER/DER input is affected.\n\n### Affected components\n- `pyasn1.codec.ber.decoder` — `decode()` and `StreamingDecoder`\n- `pyasn1.codec.cer.decoder` and `pyasn1.codec.der.decoder`, which inherit\n  the same tag parsing\n- `pyasn1.type.tag` — `Tag`/`TagSet` reprs could raise `ValueError` when\n  rendering oversized tag IDs (reachable through decoder error paths)\n\nThe encoders and the `pyasn1.codec.native` codec are not affected.\n\n### Patches\nFixed in 0.6.4. Long-form tag IDs are now limited to 20 octets (140-bit tag IDs, matching the existing OID arc limit); oversized tags are rejected with `PyAsn1Error`. Tag ID rendering in reprs and error messages was additionally hardened against the interpreter's integer-to-string conversion limit.\n\n### Workarounds\nBound the size of untrusted input passed to `decode()` before calling it.","affected":[{"package":{"name":"pyasn1","ecosystem":"PyPI","purl":"pkg:pypi/pyasn1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.4"}]}],"versions":["0.0.10a","0.0.11a","0.0.12a","0.0.13","0.0.13a","0.0.13b","0.0.6a","0.0.9a","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.1","0.2.2","0.2.3","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.5.0","0.5.1","0.6.0","0.6.1","0.6.2","0.6.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m4p7-r5rc-7g4j/GHSA-m4p7-r5rc-7g4j.json"}}],"references":[{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59884"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5"},{"type":"PACKAGE","url":"https://github.com/pyasn1/pyasn1"},{"type":"WEB","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyasn1/PYSEC-2026-3455.yaml"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2026-07-21T19:10:11Z","nvd_published_at":"2026-07-14T17:17:14Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}