GHSA-m4p7-r5rc-7g4j

    Dashboard / Vulnerabilities / GHSA-m4p7-r5rc-7g4j

    GHSA-m4p7-r5rc-7g4j

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

    Details: ### Impact The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled `ValueError` (integer string conversion limit) while the decoder formats error messages, violating the documented `PyAsn1Error` contract and potentially bypassing caller error handling. Any application decoding untrusted BER/CER/DER input is affected. ### Affected components - `pyasn1.codec.ber.decoder` — `decode()` and `StreamingDecoder` - `pyasn1.codec.cer.decoder` and `pyasn1.codec.der.decoder`, which inherit the same tag parsing - `pyasn1.type.tag` — `Tag`/`TagSet` reprs could raise `ValueError` when rendering oversized tag IDs (reachable through decoder error paths) The encoders and the `pyasn1.codec.native` codec are not affected. ### Patches Fixed in 0.6.4. Long-form tag IDs are now limited to 20 octets (140-bit tag IDs, matching the existing OID arc limit); oversized tags are rejected with `PyAsn1Error`. Tag ID rendering in reprs and error messages was additionally hardened against the interpreter's integer-to-string conversion limit. ### Workarounds Bound the size of untrusted input passed to `decode()` before calling it.

    Affected packages

    Package

    Name: pyasn1

    Purl: pkg:pypi/pyasn1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.6.4

    Affected versions

    0.0.10a
    0.0.11a
    0.0.12a
    0.0.13
    0.0.13a
    0.0.13b
    0.0.6a
    0.0.9a

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m4p7-r5rc-7g4j | CVE-DB