Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.27% | — | Erlang OTPAIErlang Asn1AI | 22/9/2026 | 24/9/2026 | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:dec_subidentifiers/3 in lib/asn1/src/asn1rtt_ber.erl and the equivalent PER helper… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Wildfly Elytron-asn1AI | 18/9/2026 | 29/9/2026 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper… | |
| Analizada | Alta (7.5) | 0.62% | — | Pyasn1 | 14/7/2026 | 21/7/2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through… | |
| Analizada | Alta (7.5) | 0.62% | — | Pyasn1 | 14/7/2026 | 21/7/2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to… | |
| Analizada | Alta (7.5) | 0.62% | — | Pyasn1 | 14/7/2026 | 21/7/2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing… | |
| Aplazada | Alta (8.2) | 0.33% | — | Mouse07410 Asn1cAI | 29/5/2026 | 21/7/2026 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to… | |
| Modificada | Alta (7.5) | 0.93% | — | Pyasn1 | 18/3/2026 | 10/9/2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or… | |
| Analizada | Crítica (9.2) | 0.34% | — | Jonathanwilbur Asn1-ts | 21/2/2026 | 17/6/2026 | ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6. | |
| Modificada | Alta (7.5) | 0.77% | — | Pyasn1Debian Linux | 16/1/2026 | 9/9/2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2. | |
| Analizada | Alta (7.5) | 1.2% | — | GNU Libtasn1 | 7/1/2026 | 17/6/2026 | Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Mouse07410 Asn1cAIVLM Asn1cAI | 22/8/2025 | 17/6/2026 | An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing incorrect or malicious input to be processed. | |
| Aplazada | Media (6.9) | 0.23% | — | Ts-asn1-der Project Ts-asn1-derAI | 7/4/2025 | 17/6/2026 | ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead to denial on service for absolute values in the range 2**31 -- 2**32 - 1. The arithmetic in the numBitLen didn't take into account that values in this range could result in a negative result… | |
| Aplazada | Media (5.3) | 1.3% | — | GNU Libtasn1AIGnutlsAI | 10/2/2025 | 17/6/2026 | A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate,… | |
| Aplazada | Media (5.3) | 1.1% | — | GNU Libtasn1AI | 10/2/2025 | 30/6/2026 | A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of… | |
| Modificada | Media (5.5) | 0.30% | — | Asn1c Project Asn1c | 18/7/2023 | 17/6/2026 | An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (5.5) | 0.30% | — | Asn1c Project Asn1c | 18/7/2023 | 17/6/2026 | Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c. | |
| Modificada | Crítica (9.1) | 2.2% | — | GNU Libtasn1Fedoraproject FedoraDebian Linux | 24/10/2022 | 17/6/2026 | GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. | |
| Modificada | Alta (7.5) | 1.3% | — | Simple Asn1 Project Simple Asn1 | 27/12/2021 | 17/6/2026 | An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f. | |
| Modificada | Alta (7.5) | 1.4% | — | Asn1 DER Project Asn1 DER | 26/8/2019 | 17/6/2026 | An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length field. | |
| Modificada | Media (5.5) | 2.0% | — | GNU Libtasn1 | 20/8/2018 | 17/6/2026 | GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a… | |
| Modificada | Alta (7.5) | 2.8% | — | GNU Libtasn1Debian LinuxFedoraproject Fedora | 22/1/2018 | 17/6/2026 | An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS. | |
| Modificada | Media (6.5) | 1.1% | — | Asn1c Project Asn1c | 20/8/2017 | 17/6/2026 | The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file. | |
| Modificada | Alta (7.5) | 5.0% | — | GNU Libtasn1 | 2/7/2017 | 17/6/2026 | The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack. | |
| Modificada | Alta (8.8) | 5.6% | — | GNU Libtasn1Debian LinuxApache Bookkeeper | 22/5/2017 | 17/6/2026 | Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility. | |
| Modificada | Crítica (9.8) | 10% | — | Objective Systems Asn1c | 19/7/2016 | 17/6/2026 | Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow), on a system running an application compiled by ASN1C, via crafted ASN.1 data. |