<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:06:31.555018+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15492</id>
    <title>bdu:2026-15492</title>
    <updated>2026-10-03T18:06:33.091266+00:00</updated>
    <content>bdu:2026-15492</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-59885</id>
    <title>BELL-CVE-2026-59885</title>
    <updated>2026-10-03T18:06:33.091368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: py3-asn1, Alpaquita:25: py3-asn1, Alpaquita:stream: py3-asn1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-59885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-59885</id>
    <title>BREW-ansible-CVE-2026-59885 — pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service</title>
    <updated>2026-10-03T18:06:33.091404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>### Impact
The BER/CER/DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload (tens of kilobytes) containing an OID with many arcs consumes seconds of CPU per decode() call, allowing denial of service in any application that decodes untrusted ASN.1 data (certificates, LDAP, SNMP, Kerberos, etc.). The corresponding encoders have the same quadratic behavior, reachable when an application re-encodes previously decoded attacker-supplied values.</p>
<p>The arc-size limit introduced for CVE-2026-23490 bounds the byte length of an individual arc but not the number of arcs, so it does not mitigate this issue.</p>
<p>### Affected components
ObjectIdentifierPayloadDecoder and RelativeOIDPayloadDecoder in pyasn1/codec/ber/decoder.py; ObjectIdentifierEncoder and RelativeOIDEncoder in pyasn1/codec/ber/encoder.py. The CER and DER codecs inherit these and are equally affected.</p>
<p>### Patches
Fixed in pyasn1 0.6.4: arc accumulation in both decoders and encoders now runs in linear time.</p>
<p>### Workarounds
Limit the size of untrusted ASN.1 input before decoding.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-59885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</id>
    <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T18:06:33.091443+00:00</updated>
    <content>certfr-2026-avi-1249</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</id>
    <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
    <updated>2026-10-03T18:06:33.091462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336636</id>
    <title>EUVD-2026-336636</title>
    <updated>2026-10-03T18:06:33.091484+00:00</updated>
    <content>EUVD-2026-336636</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336636"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59885</id>
    <title>fkie_cve-2026-59885</title>
    <updated>2026-10-03T18:06:33.091497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8ppf-4f7h-5ppj</id>
    <title>GHSA-8ppf-4f7h-5ppj — pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service</title>
    <updated>2026-10-03T18:06:33.091522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyasn1</p>
<p>### Impact
The BER/CER/DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload (tens of kilobytes) containing an OID with many arcs consumes seconds of CPU per decode() call, allowing denial of service in any application that decodes untrusted ASN.1 data (certificates, LDAP, SNMP, Kerberos, etc.). The corresponding encoders have the same quadratic behavior, reachable when an application re-encodes previously decoded attacker-supplied values.</p>
<p>The arc-size limit introduced for CVE-2026-23490 bounds the byte length of an individual arc but not the number of arcs, so it does not mitigate this issue.</p>
<p>### Affected components
ObjectIdentifierPayloadDecoder and RelativeOIDPayloadDecoder in pyasn1/codec/ber/decoder.py; ObjectIdentifierEncoder and RelativeOIDEncoder in pyasn1/codec/ber/encoder.py. The CER and DER codecs inherit these and are equally affected.</p>
<p>### Patches
Fixed in pyasn1 0.6.4: arc accumulation in both decoders and encoders now runs in linear time.</p>
<p>### Workarounds
Limit the size of untrusted ASN.1 input before decoding.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8ppf-4f7h-5ppj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59885</id>
    <title>msrc_CVE-2026-59885 — pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service</title>
    <updated>2026-10-03T18:06:33.091551+00:00</updated>
    <content>msrc_CVE-2026-59885</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-59885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3198</id>
    <title>OESA-2026-3198 — python-pyasn1 security update</title>
    <updated>2026-10-03T18:06:33.091569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-pyasn1, openEuler:22.03-LTS-SP4: python-pyasn1, openEuler:24.03-LTS-SP1: python-pyasn1, openEuler:24.03-LTS-SP3: python-pyasn1, openEuler:24.03-LTS-SP4: python-pyasn1</p>
<p>Abstract Syntax Notation One (ASN.1) is a technology for exchanging structured data in a universally understood, hardware agnostic way. Many industrial, security and telephony applications heavily rely on ASN.1. The pyasn1 library implements ASN.1 support in pure-Python.

Security Fix(es):</p>
<p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.(CVE-2026-59884)</p>
<p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.(CVE-2026-59885)</p>
<p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11318-1</id>
    <title>openSUSE-SU-2026:11318-1 — python313-pyasn1-0.6.4-1.1 on GA media</title>
    <updated>2026-10-03T18:06:33.091616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-pyasn1-0.6.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11318-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3456</id>
    <title>PYSEC-2026-3456</title>
    <updated>2026-10-03T18:06:33.091638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyasn1</p>
<p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:40236</id>
    <title>RHSA-2026:40236 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T18:06:33.091660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-pyasn1: pyasn1: Denial of Service via crafted BER input pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:40236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22765-1</id>
    <title>SUSE-SU-2026:22765-1 — Security update for python-pyasn1</title>
    <updated>2026-10-03T18:06:33.091681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-pyasn1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22765-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59885</id>
    <title>UBUNTU-CVE-2026-59885</title>
    <updated>2026-10-03T18:06:33.091701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: pyasn1, Ubuntu:Pro:16.04:LTS: pyasn1, Ubuntu:Pro:18.04:LTS: pyasn1, Ubuntu:Pro:20.04:LTS: pyasn1, Ubuntu:22.04:LTS: pyasn1, Ubuntu:24.04:LTS: pyasn1, Ubuntu:26.04:LTS: pyasn1</p>
<p>pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59885"/>
  </entry>
</feed>
