CVE-2026-27452

MEDIUM

ASN.1 TypeScript ESM <=11.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
jonathanwilbur/asn1-ts < 11.0.6
Published Feb 21, 2026
Tracked Since Feb 21, 2026