pyasn1 <0.6.2: DOS via excessive RELATIVE-OID octets
CVE-2026-23490 Published on January 16, 2026
pyasn1 has a DoS vulnerability in decoder
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
Vulnerability Analysis
CVE-2026-23490 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2026-23490
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-23490 are published in these products:
Affected Versions
pyasn1:- Version < 0.6.2 is affected.
- Version 0:0.6.3-1.el8ap and below * is unaffected.
- Version 0:4.6.26-1.el8ap and below * is unaffected.
- Version 0:0.6.3-1.el9ap and below * is unaffected.
- Version 0:4.6.26-1.el9ap and below * is unaffected.
- Version 0:0.6.3-1.el9ap and below * is unaffected.
- Version 0:4.7.9-1.el9ap and below * is unaffected.
- Version 0:4.16.0-13.el10_1.2 and below * is unaffected.
- Version 0:0.6.2-1.el10_1 and below * is unaffected.
- Version 0:4.16.0-5.el10_0.8 and below * is unaffected.
- Version 0:0.6.2-1.el10_0.1 and below * is unaffected.
- Version 0:4.1.1-61.el7_9.23 and below * is unaffected.
- Version 0:0.1.9-7.el7_9.2 and below * is unaffected.
- Version 0:4.2.1-129.el8_10.21 and below * is unaffected.
- Version 0:0.3.7-6.el8_10.1 and below * is unaffected.
- Version 0:4.9.0-54.el8_10.28 and below * is unaffected.
- Version 0:0.3.7-6.el8_2.1 and below * is unaffected.
- Version 0:4.2.1-65.el8_4.27 and below * is unaffected.
- Version 0:0.3.7-6.el8_4.1 and below * is unaffected.
- Version 0:4.1.1-90.el8_4.23 and below * is unaffected.
- Version 0:4.2.1-65.el8_4.27 and below * is unaffected.
- Version 0:0.3.7-6.el8_4.1 and below * is unaffected.
- Version 0:4.1.1-90.el8_4.23 and below * is unaffected.
- Version 0:4.2.1-89.el8_6.21 and below * is unaffected.
- Version 0:0.3.7-6.el8_6.1 and below * is unaffected.
- Version 0:4.2.1-89.el8_6.21 and below * is unaffected.
- Version 0:0.3.7-6.el8_6.1 and below * is unaffected.
- Version 0:4.9.0-16.el8_6.20 and below * is unaffected.
- Version 0:4.2.1-89.el8_6.21 and below * is unaffected.
- Version 0:0.3.7-6.el8_6.1 and below * is unaffected.
- Version 0:4.9.0-16.el8_6.20 and below * is unaffected.
- Version 0:4.2.1-112.el8_8.16 and below * is unaffected.
- Version 0:0.3.7-6.el8_8.1 and below * is unaffected.
- Version 0:4.9.0-40.el8_8.16 and below * is unaffected.
- Version 0:4.2.1-112.el8_8.16 and below * is unaffected.
- Version 0:0.3.7-6.el8_8.1 and below * is unaffected.
- Version 0:4.9.0-40.el8_8.16 and below * is unaffected.
- Version 0:4.10.0-98.el9_7.5 and below * is unaffected.
- Version 0:0.4.8-7.el9_7 and below * is unaffected.
- Version 0:4.10.0-20.el9_0.28 and below * is unaffected.
- Version 0:0.4.8-6.el9_0.1 and below * is unaffected.
- Version 0:4.10.0-43.el9_2.19 and below * is unaffected.
- Version 0:0.4.8-6.el9_2.1 and below * is unaffected.
- Version 0:4.10.0-62.el9_4.22 and below * is unaffected.
- Version 0:0.4.8-6.el9_4.1 and below * is unaffected.
- Version 0:4.10.0-86.el9_6.15 and below * is unaffected.
- Version 0:0.4.8-6.el9_6.1 and below * is unaffected.
- Version 0:0.5.1-4.el9 and below * is unaffected.
- Version 0:0.5.1-4.el9 and below * is unaffected.
- Version 0:0.4.6-5.el8ost and below * is unaffected.
- Version 1782353093 and below * is unaffected.
- Version 1777398315 and below * is unaffected.
- Version 1777402264 and below * is unaffected.
- Version 1777296732 and below * is unaffected.
- Version 1777391447 and below * is unaffected.
- Version 1780102732 and below * is unaffected.
- Version 1774002867 and below * is unaffected.
- Version 1778677745 and below * is unaffected.
- Version 1778666124 and below * is unaffected.
- Version 1780069135 and below * is unaffected.
- Version 1780069127 and below * is unaffected.
- Version 1778239104 and below * is unaffected.
- Version 1778263407 and below * is unaffected.
- Version 1778791600 and below * is unaffected.
- Version 1779123334 and below * is unaffected.
- Version 1782471587 and below * is unaffected.
- Version 1782471672 and below * is unaffected.
- Version 1782471678 and below * is unaffected.
- Version 1782471731 and below * is unaffected.
- Version 1782471732 and below * is unaffected.
- Version 1782471849 and below * is unaffected.
- Version 1782471734 and below * is unaffected.
- Version 1782471879 and below * is unaffected.
- Version 1782472374 and below * is unaffected.
- Version 1782471606 and below * is unaffected.
- Version 1782471796 and below * is unaffected.
- Version 1782471661 and below * is unaffected.
- Version 1782471672 and below * is unaffected.
- Version 1782471731 and below * is unaffected.
- Version 1782471929 and below * is unaffected.
- Version 1782471753 and below * is unaffected.
- Version 1782471740 and below * is unaffected.
- Version 1782471834 and below * is unaffected.
- Version 1782471730 and below * is unaffected.
- Version 1782471835 and below * is unaffected.
- Version 1782471697 and below * is unaffected.
- Version 1782387549 and below * is unaffected.
- Version 1780560117 and below * is unaffected.
- Version 1780914886 and below * is unaffected.
- Version 1773670137 and below * is unaffected.
- Version 1777452540 and below * is unaffected.
- Version 1777407251 and below * is unaffected.
- Version 1777436150 and below * is unaffected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2026-23490
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| pip | pyasn1 | <= 0.6.2 | 0.6.3 |
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.