CVE-2026-59885
HighAdvisory
Published 14 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.003
- 27th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 421
- of 17,781 indexed, latest versions
- Container images
- 413
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Carried by container images the latest versions of 421 of 17,781 indexed charts deploy, on 413 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pyasn1pypi | 0.1.9, 0.3.7, 0.4.1, 0.4.2+12 more | 0.6.4 | 413 |
| pyasn1deb | 0.4.2-3, 0.4.8-1, 0.4.8-1ubuntu0.2, 0.4.8-3+3 more | 0.4.8-1ubuntu0.3, 0.4.8-3+deb12u3, 0.4.8-4ubuntu0.3, 0.6.1-1+deb13u3 | 18 |
- OSV records
- DEBIAN-CVE-2026-59885GHSA-8ppf-4f7h-5ppjUBUNTU-CVE-2026-59885
- Also known as
- PYSEC-2026-3456, USN-8712-1
Charts affected
421 by stars
Container images carrying it
413 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| linuxserver/ | 241009026e6f | pyasn1 | 0.6.4 | 1 |
| linuxserver/ | 938810eca3d3 | pyasn1 | 0.6.4 | 1 |
| linuxserver/ | 89cd8d5fb1ac | pyasn1 | 0.6.4 | 1 |
| linuxserver/ | c4d2766b9eb7 | pyasn1 | 0.6.4 | 1 |
| linuxserver/ | 052eac68ccc0 | pyasn1 | 0.6.4 | 1 |
| linuxserver/ | 0ac871624394 | pyasn1 pyasn1 | no fix listed 0.6.4 | 1 |
| linuxserver/ | 2ce561a95e7b | pyasn1 pyasn1 | no fix listed 0.6.4 | 1 |
| linuxserver/ | e48b479c1891 | pyasn1 | 0.6.4 | 1 |
| litellm/ | 09b217802ded | pyasn1 | 0.6.4 | 1 |
| localstack/ | 9d278167f2b7 | pyasn1 | 0.6.4 | 1 |
| lsstsqre/ | b75bf8aaafa4 | pyasn1 | 0.6.4 | 1 |
| lsstsqre/ | 19c2dfc4e4ff | pyasn1 | 0.6.4 | 1 |
| lsstsqre/ | 5e0ade6bed1c | pyasn1 | 0.6.4 | 1 |
| lsstsqre/ | e139fde946d7 | pyasn1 | 0.6.4 | 1 |
| lsstsqre/ | e9feb99f524d | pyasn1 | 0.6.4 | 1 |
| marcoimme/ | b6035c0721a8 | pyasn1 | 0.6.4 | 1 |
| matrixdotorg/ | c3c4a9de2a0b | pyasn1 | 0.6.4 | 1 |
| matrixdotorg/ | cb89c0f17ba1 | pyasn1 | 0.6.4 | 1 |
| matrixdotorg/ | def97fd537d8 | pyasn1 | 0.6.4 | 1 |
| mindsdb/ | 163011c09299 | pyasn1 | 0.6.4 | 1 |
| mirrorgitlabcontainers/ | 9efd73993c34 | pyasn1 | 0.6.4 | 1 |
| mozilla/ | 016162bf39d8 | pyasn1 | 0.6.4 | 1 |
| mvitale1989/ | 1504ccda06df | pyasn1 | 0.6.4 | 1 |
| netboxcommunity/ | 3d652dca5351 | pyasn1 | 0.6.4 | 1 |
| netboxcommunity/ | 9bf83b350a89 | pyasn1 | 0.6.4 | 1 |
| networktocode/ | ed484336b1ad | pyasn1 | 0.6.4 | 1 |
| ngoduykhanh/ | 099371dd9ba6 | pyasn1 | 0.6.4 | 1 |
| ngoduykhanh/ | 9898a7cf37d2 | pyasn1 | 0.6.4 | 1 |
| nlmacamp/ | 5dbb8589f824 | pyasn1 | 0.6.4 | 1 |
| octoprint/ | 106c26efcd8a | pyasn1 | 0.6.4 | 1 |
| odaniait/ | 3fff8a8570ec | pyasn1 | 0.6.4 | 1 |
| odavid/ | e7ab3bbc948e | pyasn1 | 0.6.4 | 1 |
| oled01/ | 05d3e398e675 | pyasn1 | 0.6.4 | 1 |
| omecproject/ | d109a8e57e71 | pyasn1 | 0.6.4 | 1 |
| opea/ | 38c51b791efa | pyasn1 | 0.6.4 | 1 |
| opea/ | 58f91683892d | pyasn1 | 0.6.4 | 1 |
| opea/ | e2436483b73d | pyasn1 | 0.6.4 | 1 |
| opea/ | 3eaa91849512 | pyasn1 | 0.6.4 | 1 |
| opea/ | fe08165d7770 | pyasn1 | 0.6.4 | 1 |
| openbas/ | a277796d9724 | pyasn1 | 0.6.4 | 1 |
| opencsghq/ | 2f03fead54db | pyasn1 | 0.6.4 | 1 |
| opencsghq/ | af7191a9cf8a | pyasn1 | 0.6.4 | 1 |
| opencsghq/ | 2cd29671a03e | pyasn1 | 0.6.4 | 1 |
| opencsghq/ | 47e22aa71870 | pyasn1 | 0.6.4 | 1 |
| opencsghq/ | b4e849fcf94a | pyasn1 | 0.6.4 | 1 |
| opendatacube/ | 91870111837c | pyasn1 pyasn1 | no fix listed 0.6.4 | 1 |
| opendatacube/ | 1b90cdf68831 | pyasn1 pyasn1 | no fix listed 0.6.4 | 1 |
| openstackhelm/ | e07d75953d2e | pyasn1 | 0.6.4 | 1 |
| openvpn/ | 2253c10ec652 | pyasn1 pyasn1 | 0.4.8-4ubuntu0.3 0.6.4 | 1 |
| phntom/ | 49b6488f618b | pyasn1 | 0.6.4 | 1 |