CVE-2026-30922Disclosure(pyasn1 / pyasn1)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyasn1

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pyasn1

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-21: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-21: 103-1803-21
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure3
2026-03-211
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-30922: pyasn1: DoS via Unbounded Recursion https://www.openwall.com/lists/oss-security/2026/03/20/4 when decoding ASN.1 data with deeply nested structures

    Post summary

    The post announces CVE-2026-30922 as a denial‑of‑service flaw in the pyasn1 library caused by unbounded recursion when decoding deeply nested ASN.1 data, without providing exploitation or mitigation details.

    00051526
    4.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30922 Denial of Service via Uncontrolled Recursion in pyasn1 Library Before 0.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30922 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-30922 as a denial‑of‑service issue in the pyasn1 library, providing only surface‑level details and links to vulnerability information, without any PoC, exploit code, or active exploitation claims.

    0000038
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-30922 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-30922 #CVE-2026-30922 #CVE #High  #CyberSecurity #InfoSec https://t.co/LYlSgUugV5

    Post summary

    The tweet announces the new CVE-2026-30922, providing basic severity and scope information along with a link to the NVD entry for further details.

    0000028
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30922 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion … https://www.cve.org/CVERecord?id=CVE-2026-30922

    Post summary

    The post announces CVE-2026-30922, describing a Denial of Service vulnerability in pyasn1 caused by uncontrolled recursion, without mentioning exploitation, PoC, or mitigations.

    0000070
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyasn1pyasn1-python-

Explore more