CVE-2026-30922: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-30922 is a Denial of Service (DoS) vulnerability in the pyasn1 Python library caused by uncontrolled recursion during ASN.1 decoding. All versions of pyasn1 up to and including 0.6.2 are affected; version 0.6.3 contains the fix. The vulnerability was discovered by Kevin Tu of TMIR at ByteDance and publicly disclosed on March 17, 2026 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, oss-security).

Technical details

The root cause is uncontrolled recursion (CWE-674) in the BER/CER/DER decoder's decodeFun callback, which is invoked recursively for every nested ASN.1 component without any depth tracking or limit enforcement. Three specific vulnerable code paths exist: indefLenValueDecoder (line 998), valueDecoder (lines 786 and 907), and _decodeComponentsSchemaless (line 661) — none of which pass a depth parameter or check against a maximum nesting limit. An unauthenticated remote attacker can craft a payload of deeply nested SEQUENCE (0x30) or SET (0x31) tags with Indefinite Length (0x80) markers (e.g., b'\x30\x80' * 50000), causing the Python interpreter to crash with a RecursionError or exhaust available memory. The fix introduces a MAX_NESTING_DEPTH = 100 constant and a _nestingLevel counter passed through options, raising a PyAsn1Error when the limit is exceeded (GitHub Advisory, GitHub Commit).

Impact

Successful exploitation crashes the worker process or thread handling the ASN.1 parsing request, resulting in a Denial of Service for any application relying on pyasn1 to parse untrusted data — including LDAP, SNMP, Kerberos, and X.509 certificate parsers. A payload under 10 KB (e.g., 9.77 KB for 50,000 nested tags) is sufficient to trigger a RecursionError; in environments with elevated recursion limits, the attack instead causes server-wide memory exhaustion, with RAM consumption scaling linearly with nesting depth (payloads under 200 KB can consume hundreds of megabytes). There is no confidentiality or integrity impact — the vulnerability is purely an availability issue (GitHub Advisory, oss-security).

Exploitability

A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory, demonstrating that a ~10 KB payload is sufficient to crash a vulnerable service. The EPSS score is 0.04% (low probability of near-term exploitation), and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No authentication or user interaction is required, making it trivially exploitable by any network-accessible attacker against services parsing untrusted ASN.1 data (GitHub Advisory).

Exploitation steps

  1. Identify target services: Locate network-accessible services that use pyasn1 versions ≤ 0.6.2 to parse untrusted ASN.1 data — common targets include LDAP servers, SNMP agents, Kerberos implementations, and X.509/TLS certificate parsers built on Python.
  2. Craft the malicious payload: Generate a recursion bomb by repeating the indefinite-length SEQUENCE tag bytes: payload = b'\x30\x80' * depth (e.g., depth = 50000 produces a ~9.77 KB payload). Alternatively, use nested SET tags (b'\x31\x80') or a mix of both.
  3. Deliver the payload: Send the crafted ASN.1 data to the target service over the network via the appropriate protocol (e.g., embed it in an LDAP bind request, SNMP packet, or TLS ClientHello certificate field).
  4. Trigger the crash: The pyasn1 decoder recursively calls decodeFun for each nested tag without depth checking, eventually hitting Python's recursion limit and raising an unhandled RecursionError, crashing the worker process. In high-recursion-limit environments, memory is exhausted instead.
  5. Achieve DoS: The service worker handling the request terminates, causing a denial of service. Repeated requests can prevent service recovery if no process supervisor is in place (GitHub Advisory, oss-security).

Indicators of compromise

  • Logs: Python tracebacks containing RecursionError or maximum recursion depth exceeded in application logs for services using pyasn1; MemoryError exceptions in logs indicating OOM conditions during ASN.1 parsing.
  • Process: Unexpected termination or restart of service worker processes (e.g., LDAP, SNMP, or Python-based TLS services); process supervisors (systemd, supervisord) logging repeated restarts of the affected service.
  • Network: Inbound network traffic containing repeated 0x30 0x80 or 0x31 0x80 byte sequences (indefinite-length SEQUENCE/SET tags) in ASN.1-bearing protocols; unusually small but high-frequency requests to ASN.1-parsing endpoints.
  • System: Sudden spikes in memory consumption by the affected Python process immediately before a crash, particularly if the process reaches system memory limits.

Mitigation and workarounds

The primary remediation is to upgrade pyasn1 to version 0.6.3 or later, which introduces a MAX_NESTING_DEPTH = 100 limit enforced via a _nestingLevel counter in the decoder options (GitHub Commit). Downstream products have also released patches: OpenVPN Access Server 3.2.0 (OpenVPN Release Notes), multiple IBM products including Maximo Application Suite, CloudPak for AIOps, QRadar Suite, and Business Automation Insights (IBM Advisory), and distributions including Ubuntu (USN-8134-1), Debian, SUSE, Red Hat, and Amazon Linux. As a short-term workaround where patching is not immediately feasible, restrict network access to services that parse untrusted ASN.1 data and consider implementing input size limits at the application or network layer.

Community reactions

The vulnerability was disclosed via the oss-security mailing list on March 20, 2026 by Alan Coopersmith of Oracle, crediting Kevin Tu of TMIR at ByteDance as the discoverer (oss-security). The issue received broad attention from Linux distribution security teams, with rapid patch releases from Ubuntu, Debian, SUSE, Red Hat, Rocky Linux, AlmaLinux, Amazon Linux, and Mageia. Social media discussion was noted on Mastodon and Bluesky within hours of disclosure. Multiple IBM product teams issued security bulletins acknowledging the dependency on vulnerable pyasn1 versions, reflecting the library's wide use in enterprise software stacks.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pyasn1: 0.4.8-3+deb12u2

Fixed

sid

pyasn1: 0.6.3-1

Fixed

trixie

pyasn1: 0.6.1-1+deb13u2

Fixed

RHEL / CentOS

Fixed

OpenShift

openshift4/ztp-site-generate-rhel8

Affected

RHEL 8

:appstream:fence-agents-0:4.2.1-129.el8_10.25.src

Fixed

RHEL 9

:appstream:fence-agents-0:4.10.0-43.el9_2.22.src

Fixed

RHEL 10

fence-agents-0:4.16.0-5.el10_0.9.src

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management