A high-severity denial-of-service vulnerability tracked as CVE-2026-30922 was disclosed in the Python pyasn1 package, where uncontrolled recursion during ASN.1 decoding can crash applications or exhaust memory. The flaw affects pyasn1 0.6.2 and earlier and was fixed in 0.6.3. According to the advisory, crafted ASN.1 input with deeply nested SEQUENCE or SET tags and indefinite-length markers can trigger RecursionError exceptions or out-of-memory conditions during decoding.
The issue stems from recursive decoder paths that do not enforce a recursion-depth limit, including indefinite-length decoding as well as schema-based and schemaless decoding. Services that parse untrusted ASN.1 data may be remotely exposed, including software handling LDAP, SNMP, Kerberos, and X.509 data. The vulnerability is classified as CWE-674 and carries a CVSS 3.0 score of 7.5; the issue was reported by Kevin Tu of TMIR at ByteDance and documented in both the upstream GitHub security advisory and the oss-security disclosure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
An oss-sec post publicly disclosed CVE-2026-30922 and provided technical details on multiple affected decoder code paths, including indefinite-length, schema-based, and schemaless decoding. The disclosure noted that remotely reachable services such as LDAP, SNMP, Kerberos, and X.509 parsers may be exposed if they rely on pyasn1.
The vulnerability was fixed in pyasn1 version 0.6.3, which addressed recursive decoder paths that lacked recursion-depth limits. The fix mitigates crashes and out-of-memory conditions triggered by crafted nested ASN.1 data.
A GitHub security advisory was published for CVE-2026-30922, describing a high-severity denial-of-service vulnerability in pyasn1 via unbounded recursion. The advisory identifies the flaw as affecting pyasn1 through version 0.6.2.
Kevin Tu of TMIR at ByteDance reported a denial-of-service flaw in pyasn1 caused by uncontrolled recursion during ASN.1 decoding of deeply nested structures. The issue affects pyasn1 0.6.2 and earlier and can crash or exhaust memory in services parsing untrusted ASN.1 data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.