CVE-2026-23490·Python vulnerability
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
- Severity
- high
- Software
- Python
- Fixed in
- 0.6.2
- Published
- 2026-01-16
Affected versions
Until: 0.6.2
Fixed in: 0.6.2
How to fix this CVE
Update the pyasn1 library to version 0.6.2 or later to remediate this denial-of-service vulnerability. Applications using pyasn1 for ASN.1 decoding are at risk of memory exhaustion when processing specially crafted RELATIVE-OID structures. Prioritize this update in your Python environment to prevent service disruption from resource exhaustion attacks.
sudo dnf update python3-pyasn1 && python3 -m pip install --upgrade pyasn1>=0.6.2Defensia detects this vulnerability
How to check if you are affected
- Step 1: Check installed pyasn1 version by running: python3 -c "import pyasn1; print(pyasn1.__version__)"
- Step 2: Verify if pyasn1 is used in production applications by searching: grep -r "from pyasn1" /path/to/your/application/code or pip show pyasn1
- Step 3: Review application logs for signs of memory exhaustion, such as MemoryError exceptions or OOM killer events: grep -i "memory\|oom" /var/log/syslog /var/log/messages
- Step 4: After applying the update, re-run the version check command to confirm pyasn1 is at version 0.6.2 or higher
FAQ
What is CVE-2026-23490?
CVE-2026-23490 is a denial-of-service vulnerability in pyasn1 (a Python ASN.1 library) that allows attackers to exhaust memory by sending malformed RELATIVE-OID structures with excessive continuation octets, causing applications to crash or become unresponsive.
Is CVE-2026-23490 being actively exploited?
No, CVE-2026-23490 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available, though organizations should still apply the patch to prevent potential future exploitation.
What versions of Python are affected by CVE-2026-23490?
All versions of pyasn1 prior to 0.6.2 are vulnerable. The exact lower bound is not specified, but it's recommended to upgrade any pyasn1 installation to 0.6.2 or later regardless of the current version.
How do I check if my server is vulnerable to CVE-2026-23490?
Run 'python3 -c "import pyasn1; print(pyasn1.__version__)"' and compare the version to 0.6.2. If the installed version is lower than 0.6.2, your server is vulnerable.
Does Defensia detect CVE-2026-23490?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If pyasn1 is installed on a monitored server, CVE-2026-23490 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
- https://lists.debian.org/debian-lts-announce/2026/02/msg00002.html
- https://access.redhat.com/errata/RHSA-2026:13508
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-23490. Free for 1 server.
Get started free