PT-2026-81474 · Pypi · Eml-Parser

·

CVE-2026-55618

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions eml parser versions prior to 3.0.2
Description The clean found uri() function in eml parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash, or period characters. This causes valid encoded URLs and their host names to be rejected and omitted from extracted URL and domain lists. Consequently, security gateways and SOC pipelines relying on these lists as indicators of compromise may fail to submit hidden URLs to threat intelligence feeds, reputation services, or sandboxes, allowing malicious links to bypass inspection.
Recommendations Update to version 3.0.2.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55618
GHSA-FXGQ-9M89-CXJ9
PYSEC-2026-3831

Affected Products

Eml-Parser