SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-59886

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The pyasn1 library for Python is vulnerable to a denial-of-service condition due to improper handling of the univ.Real type, which can lead to excessive CPU and memory consumption when decoding untrusted ASN.1 data. This vulnerability can cause applications to hang during operations like printing or comparing decoded objects. Organizations using pyasn1 versions prior to 0.6.4 should prioritize upgrading to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59886
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)