CVE-2026-23490

Executive Summary

CVE-2026-23490 exposes a denial‑of‑service flaw in the pyasn1 Python library (versions <0.6.2). Malformed RELATIVE‑OID values containing excessive continuation octets trigger uncontrolled memory allocation, exhausting system resources. The issue is mitigated in pyasn1 0.6.2 and is not listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2026-01-16T19:16:19.117 - Last Modified: 2026-09-09T13:18:50.673

Original Description: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

"We must become the change we want to see."

— Mahatma Gandhi
Source: NVD