GHSA-hm4w-wwcw-mr6r

    Dashboard / Vulnerabilities / GHSA-hm4w-wwcw-mr6r

    GHSA-hm4w-wwcw-mr6r

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: pyasn1: Uncontrolled resource consumption when converting decoded REAL values

    Details: ### Impact The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large integer. Any operation that triggers float conversion on such a decoded value — prettyPrint(), str(), comparison, arithmetic, or an explicit float() call — consumes excessive CPU and memory, hanging the process. Applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects are vulnerable to denial of service. Decoding alone does not trigger the issue. ### Affected components - pyasn1.type.univ.Real — float conversion (__float__() and everything built on it: prettyPrint(), str(), comparisons, arithmetic, int()) - Reachable through the pyasn1.codec.ber, cer, and der decoders, which produce Real objects from untrusted input; also via directly constructed Real values The encoders and the native codec are not affected. Applications that never handle ASN.1 REAL values are not affected. ### Patches Fixed in pyasn1 0.6.4. Binary (base-2) values are now converted with math.ldexp(), and decimal (base-10) values with exponents beyond float range raise OverflowError without constructing huge intermediate integers. Existing behavior is preserved: out-of-range values raise OverflowError and prettyPrint() renders them as <overflow>. ### Workarounds Avoid converting, printing, or comparing decoded Real objects from untrusted sources; inspect the raw (mantissa, base, exponent) tuple instead.

    Affected packages

    Package

    Name: pyasn1

    Purl: pkg:pypi/pyasn1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.6.4

    Affected versions

    0.0.10a
    0.0.11a
    0.0.12a
    0.0.13
    0.0.13a
    0.0.13b
    0.0.6a
    0.0.9a

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hm4w-wwcw-mr6r | CVE-DB