CVE-2026-23490Disclosure(debian / debian_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • pyasn1

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
debian_linuxpyasn1

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-02: 1Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-27: 101-2802-0202-27
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-021
Patch1
2026-02-271
Disclosure1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Heads up, #SUSE Linux community! A new security advisory (2026-20482-1) drops for python-pyasn1. We're looking at CVE-2026-23490, a classic but nasty DoS issue with a 7.5 CVSS score—memory exhaustion via malformed OIDs. Read more: 👉 https://tinyurl.com/3usjhrdd #Security https://t.co/b8WOHuRgZG

    Post summary

    The tweet announces a new advisory for python-pyasn1, detailing CVE-2026-23490 as a DoS vulnerability with a 7.5 CVSS score and memory exhaustion via malformed OIDs.

    0000062
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical DoS vuln (CVE-2026-23490) in pyasn1 #Python lib. Memory exhaustion via malformed OID. #Debian 11: PATCH NOW to version 0.4.8-1+deb11u1. Read more: 👉 https://tinyurl.com/3w7d9env #security https://t.co/eYybp2XhbH

    Post summary

    The tweet announces a critical DoS vulnerability in pyasn1 and urges users to apply the Debian 11 patch to version 0.4.8-1+deb11u1 to mitigate memory exhaustion via malformed OID.

    00000148
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 URGENT: CVE-2026-23490 affects #python-pyasn1 in #SUSE Linux Enterprise 12 SP5 distributions. CVSS 7.5 - Remote DoS vulnerability requiring no authentication. Read more: 👉 https://tinyurl.com/38ehxtsn #Security https://t.co/VXXnsJ6kAj

    Post summary

    CVE-2026-23490 is a remote DoS vulnerability in python-pyasn1 on SUSE Linux Enterprise 12 SP5, CVSS 7.5, no patch or exploit info disclosed.

    0000037
    1.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Apppyasn1pyasn1-python-

Explore more