CVE-2026-59884: pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
Impact The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled ValueError (integer string conversion limit) while the decoder formats error messages, violating the documented PyAsn1Error contract and potentially bypassing caller error handling.
Any application decoding untrusted BER/CER/DER input is affected.
Affected components - pyasn1.codec.ber.decoder — decode() and StreamingDecoder - pyasn1.codec.cer.decoder and pyasn1.codec.der.decoder, which inherit the same tag parsing - pyasn1.type.tag — Tag/TagSet reprs could raise ValueError when rendering oversized tag IDs (reachable through decoder error paths)
The encoders and the pyasn1.codec.native codec are not affected.
Patches Fixed in 0.6.4. Long-form tag IDs are now limited to 20 octets (140-bit tag IDs, matching the existing OID arc limit); oversized tags are rejected with PyAsn1Error. Tag ID rendering in reprs and error messages was additionally hardened against the interpreter's integer-to-string conversion limit.
Workarounds Bound the size of untrusted input passed to decode() before calling it.
Other sources
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
— Microsoft
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pyssn1to a version that resolves this vulnerability.Fixed in 0.6.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.4.8-3 - Upgrade
Upgrade
pyasn1to a version that resolves this vulnerability.Fixed in 0.6.4 - Compensating control
Bound the size of untrusted input passed to `decode()` before calling `pyasn1.codec.ber.decoder.decode()` (and the BER/CER/DER decoders that share the BER decoder long-form tag parsing).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59884?
CVE-2026-59884 has a severity score of 7.5, classified as high.
How do I fix CVE-2026-59884?
To fix CVE-2026-59884, update pyasn1 to version 0.6.4 or later.
What type of vulnerability is CVE-2026-59884?
CVE-2026-59884 is a denial of service vulnerability in the pyasn1 library.
What is the impact of CVE-2026-59884?
The impact of CVE-2026-59884 is the potential for an attacker to cause unbounded CPU consumption.
Which software is affected by CVE-2026-59884?
The affected software is the pyasn1 library, specifically versions prior to 0.6.4.