PT-2026-81476 · Pypi · Eml-Parser
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
eml parser versions prior to 3.0.2
Description
The
noparenthesis function in eml parser/routing.py uses a regex-based fix-point loop to remove parenthesized CFWS (Comments and Folding White Space) from Received: headers. The processing time for this operation is quadratic relative to the nesting depth of the parentheses. An attacker can provide small EML files with deeply nested parentheses to cause high CPU saturation, leading to worker latency, queue backpressure, and potential service-level outages in synchronous gateways, sandboxes, and real-time triage pipelines.Recommendations
Update to version 3.0.2.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eml-Parser