Ubuntu Multiple pyasn1 Vulnerabilities Lead to Denial of Service Risks
Article Content
- •Two critical vulnerabilities in pyasn1 can lead to denial of service attacks.
- •CVE-2026-23490 and CVE-2026-30922 exploit uncontrolled recursion in ASN.1 decoding.
- •Users should update their systems to mitigate the risks associated with these vulnerabilities.
Two vulnerabilities in the pyasn1 library have been identified, allowing attackers to exploit uncontrolled recursion when decoding malformed ASN.1 data. The first vulnerability, CVE-2026-23490, was published on January 16, 2026, and can exhaust system resources, potentially leading to a denial of service. The second vulnerability, CVE-2026-30922, published on March 18, 2026, also allows for resource exhaustion through similar means. Both vulnerabilities can be triggered by specially crafted input, affecting systems that utilize pyasn1 for certificate decoding. Users are advised to update their systems to mitigate these risks. The vulnerabilities pose a significant threat to any systems relying on pyasn1, particularly in environments where certificate validation is critical. The recommended action is to apply standard system updates to ensure protection against these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu and CVE-2026-23490 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…