PT-2026-98220 · Github · Mail-Mime-Parser

CVE-2026-61816

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions zbateson/mail-mime-parser versions 2.0.0 through 3.0.5 zbateson/mail-mime-parser versions 4.0.0 through 4.0.1
Description An uncontrolled resource consumption and algorithmic complexity issue affects applications parsing untrusted emails. Three independent parsing paths exhibit super-linear costs, meaning a byte-size cap on input does not prevent resource exhaustion. A crafted message under 2 MB can cause significant CPU consumption or allocate hundreds of megabytes to several gigabytes of memory, leading to an out-of-memory kill and denial of service. The cost is incurred during the first call to getAllParts() or when reading content.
Technical details include:
  • Deep multipart nesting: The MimeParserService::findContentBoundary() function and ParserMimePartProxy::setEndBoundaryFound() function create a complexity of O(depth²).
  • Many sibling parts: The PartChildrenContainer::add() function reindexes the entire array on every call, resulting in O(n²) complexity.
  • Unbounded header buffering: The HeaderParserService::parse() function reads header lines without limits on count or total size, allowing a small message to consume gigabytes of memory.
Recommendations For versions 2.0.0 through 3.0.5, upgrade to version 3.0.6 or later. For versions 4.0.0 through 4.0.1, upgrade to version 4.0.2 or later. Restrict exposure of the parser to untrusted input. Run parsing under a constrained memory limit and execution time limit.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61816
GHSA-F6V3-2QMR-VFJX

Affected Products

Mail-Mime-Parser