Advisories for Pypi/Pyssn1 package

2026

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID …