
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30922 is a Denial of Service (DoS) vulnerability in the pyasn1 Python library caused by uncontrolled recursion during ASN.1 decoding. All versions of pyasn1 up to and including 0.6.2 are affected; version 0.6.3 contains the fix. The vulnerability was discovered by Kevin Tu of TMIR at ByteDance and publicly disclosed on March 17, 2026 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, oss-security).
The root cause is uncontrolled recursion (CWE-674) in the BER/CER/DER decoder's decodeFun callback, which is invoked recursively for every nested ASN.1 component without any depth tracking or limit enforcement. Three specific vulnerable code paths exist: indefLenValueDecoder (line 998), valueDecoder (lines 786 and 907), and _decodeComponentsSchemaless (line 661) — none of which pass a depth parameter or check against a maximum nesting limit. An unauthenticated remote attacker can craft a payload of deeply nested SEQUENCE (0x30) or SET (0x31) tags with Indefinite Length (0x80) markers (e.g., b'\x30\x80' * 50000), causing the Python interpreter to crash with a RecursionError or exhaust available memory. The fix introduces a MAX_NESTING_DEPTH = 100 constant and a _nestingLevel counter passed through options, raising a PyAsn1Error when the limit is exceeded (GitHub Advisory, GitHub Commit).
Successful exploitation crashes the worker process or thread handling the ASN.1 parsing request, resulting in a Denial of Service for any application relying on pyasn1 to parse untrusted data — including LDAP, SNMP, Kerberos, and X.509 certificate parsers. A payload under 10 KB (e.g., 9.77 KB for 50,000 nested tags) is sufficient to trigger a RecursionError; in environments with elevated recursion limits, the attack instead causes server-wide memory exhaustion, with RAM consumption scaling linearly with nesting depth (payloads under 200 KB can consume hundreds of megabytes). There is no confidentiality or integrity impact — the vulnerability is purely an availability issue (GitHub Advisory, oss-security).
A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory, demonstrating that a ~10 KB payload is sufficient to crash a vulnerable service. The EPSS score is 0.04% (low probability of near-term exploitation), and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No authentication or user interaction is required, making it trivially exploitable by any network-accessible attacker against services parsing untrusted ASN.1 data (GitHub Advisory).
payload = b'\x30\x80' * depth (e.g., depth = 50000 produces a ~9.77 KB payload). Alternatively, use nested SET tags (b'\x31\x80') or a mix of both.decodeFun for each nested tag without depth checking, eventually hitting Python's recursion limit and raising an unhandled RecursionError, crashing the worker process. In high-recursion-limit environments, memory is exhausted instead.RecursionError or maximum recursion depth exceeded in application logs for services using pyasn1; MemoryError exceptions in logs indicating OOM conditions during ASN.1 parsing.0x30 0x80 or 0x31 0x80 byte sequences (indefinite-length SEQUENCE/SET tags) in ASN.1-bearing protocols; unusually small but high-frequency requests to ASN.1-parsing endpoints.The primary remediation is to upgrade pyasn1 to version 0.6.3 or later, which introduces a MAX_NESTING_DEPTH = 100 limit enforced via a _nestingLevel counter in the decoder options (GitHub Commit). Downstream products have also released patches: OpenVPN Access Server 3.2.0 (OpenVPN Release Notes), multiple IBM products including Maximo Application Suite, CloudPak for AIOps, QRadar Suite, and Business Automation Insights (IBM Advisory), and distributions including Ubuntu (USN-8134-1), Debian, SUSE, Red Hat, and Amazon Linux. As a short-term workaround where patching is not immediately feasible, restrict network access to services that parse untrusted ASN.1 data and consider implementing input size limits at the application or network layer.
The vulnerability was disclosed via the oss-security mailing list on March 20, 2026 by Alan Coopersmith of Oracle, crediting Kevin Tu of TMIR at ByteDance as the discoverer (oss-security). The issue received broad attention from Linux distribution security teams, with rapid patch releases from Ubuntu, Debian, SUSE, Red Hat, Rocky Linux, AlmaLinux, Amazon Linux, and Mageia. Social media discussion was noted on Mastodon and Bluesky within hours of disclosure. Multiple IBM product teams issued security bulletins acknowledging the dependency on vulnerable pyasn1 versions, reflecting the library's wide use in enterprise software stacks.
Fix availability across major Linux distributions and their releases.
bookworm
pyasn1: 0.4.8-3+deb12u2
sid
pyasn1: 0.6.3-1
trixie
pyasn1: 0.6.1-1+deb13u2
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."