---
cve: "CVE-2026-30922"
severity: "HIGH"
cvss: 7.5
epss: "80%"
vendor: "pyasn1"
kev: false
exploited: false
published: "2026-03-18 04:17:18"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-02T13:21:08+02:00"
---

# CVE-2026-30922

> 7.5 HIGH · 🧪 PoC

## Beschreibung

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- af65c3b92e9deeae50db4de390982dd970d87f98 (Commit)
- 25ad481c19fdb006e20485ef3fc2e5b3eff30ef0 (Commit)

## Referenzen

- <https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r>
- <https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0>
- <http://www.openwall.com/lists/oss-security/2026/03/20/4>
- <https://lists.debian.org/debian-lts-announce/2026/05/msg00001.html>
- <https://access.redhat.com/errata/RHSA-2026:10184>
- <https://access.redhat.com/errata/RHSA-2026:12176>
- <https://access.redhat.com/errata/RHSA-2026:13508>
- <https://access.redhat.com/errata/RHSA-2026:13512>
- <https://access.redhat.com/errata/RHSA-2026:13545>
- <https://access.redhat.com/errata/RHSA-2026:13553>
- <https://access.redhat.com/errata/RHSA-2026:13902>
- <https://access.redhat.com/errata/RHSA-2026:13916>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-30922) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
