{"id":"AZL-92433","summary":"CVE-2026-59884 affecting package python-pyasn1 for versions less than 0.4.8-3","details":"pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.","modified":"2026-08-31T05:26:27Z","published":"2026-07-14T17:17:14Z","upstream":["CVE-2026-59884"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59884"}],"affected":[{"package":{"name":"python-pyasn1","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-pyasn1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.8-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92433.json"}}],"schema_version":"1.9.0"}