Red Hat released Important-severity updates for python-pyasn1 to remediate CVE-2026-59886, a remotely reachable denial-of-service vulnerability triggered by crafted ASN.1 REAL values. The flaw can be exploited over the network without authentication or user interaction, with impact confined to service availability; no known exploits were reported.
Affected organizations should update RHEL 8, 9, and 10 systems across x86_64, s390x, ppc64le, and aarch64. Fixed packages include python-pyasn1 0.3.7-6.el8_10.2 for RHEL 8, python-pyasn1/python3-pyasn1/python3-pyasn1-modules 0.4.8-7.el9_8.1 for RHEL 9, and version 0.6.2-1.el10_2.1 for RHEL 10, including applicable extended-support and lifecycle channels.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Oracle published advisory ELSA-2026-59242 addressing CVE-2026-59886 for Oracle Linux 9. The advisory covers python3-pyasn1 and python3-pyasn1-modules packages.
Red Hat published Important advisory RHSA-2026:59329 for RHEL 7, updating affected resource-agents packages to address CVE-2026-59886. The update covers resource-agents variants and sap-cluster-connector used in high-availability environments.
Red Hat published RHSA-2026:59245, an Important RHEL 8 update addressing CVE-2026-59886 in affected python-pyasn1 packages. Tenable reported that no known exploits were available at the time of the advisory data.
Red Hat issued Important advisory RHSA-2026:59243 for RHEL 10 to fix CVE-2026-59886. Updated python-pyasn1, python3-pyasn1, and python3-pyasn1-modules packages were made available as version 0.6.2-1.el10_2.1.
Red Hat issued Important advisory RHSA-2026:59242 for RHEL 9, remediating CVE-2026-59886. Fixed python-pyasn1, python3-pyasn1, and python3-pyasn1-modules packages were released as version 0.4.8-7.el9_8.1.
Red Hat issued Important advisory RHSA-2026:59241 for RHEL 8, fixing CVE-2026-59886 in python-pyasn1. Updated packages include python3-pyasn1 and python3-pyasn1-modules version 0.3.7-6.el8_10.2.
CVE-2026-59886, a pyasn1 denial-of-service vulnerability triggered by crafted ASN.1 REAL values, was published. The flaw is remotely reachable and affects availability according to its CVSS vector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.