Skip to content

CVE-2026-23490 #36723

@tiwarishrijan

Description

@tiwarishrijan

Describe the bug

CVE-2026-23490

┌────────────────┬──────────┬──────────────────────────┬────────────┬───────────┬───────────┬──────────┬────────┬────────────┐
│ CVE            │ SEVERITY │ DIRECT                   │ DIRECT     │ AFFECTED  │ AFFECTED  │ FIXED    │ TYPE   │            │
│                │          │ DEPENDENCY               │ DEPENDENCY │ COMPONENT │ COMPONENT │ VERSIONS │        │            │
│                │          │                          │ VERSION    │ NAME      │ VERSION   │          │        │            │
├────────────────┼──────────┼──────────────────────────┼────────────┼───────────┼───────────┼──────────┼────────┼────────────┤
│ CVE-2026-23490 │ High     │ @aws-cdk/asset-awscli-v1 │ 2.2.261    │ pyasn1    │ 0.6.1     │ [0.6.2]  │ Python │            │
└────────────────┴──────────┴──────────────────────────┴────────────┴───────────┴───────────┴──────────┴────────┴────────────┘

Ref:
cdklabs/awscdk-asset-awscli#1361

Regression Issue

  • Select this option if this issue appears to be a regression.

Last Known Working CDK Library Version

No response

Expected Behavior

No CVE

Current Behavior

CVE-2026-23490

Reproduction Steps

Install CDK LIB and scan

Possible Solution

No response

Additional Information/Context

No response

AWS CDK Library version (aws-cdk-lib)

2.235.0

AWS CDK CLI version

2.1100.1

Node.js Version

v22.21.1

OS

Linux

Language

TypeScript

Language Version

No response

Other information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    aws-cdk-libRelated to the aws-cdk-lib packagebugThis issue is a bug.p2response-requestedWaiting on additional info and feedback. Will move to "closing-soon" in 7 days.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions