PT-2026-98220 · Github · Mail-Mime-Parser
CVE-2026-61816
·
Published
2026-09-24
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
zbateson/mail-mime-parser versions 2.0.0 through 3.0.5
zbateson/mail-mime-parser versions 4.0.0 through 4.0.1
Description
An uncontrolled resource consumption and algorithmic complexity issue affects applications parsing untrusted emails. Three independent parsing paths exhibit super-linear costs, meaning a byte-size cap on input does not prevent resource exhaustion. A crafted message under 2 MB can cause significant CPU consumption or allocate hundreds of megabytes to several gigabytes of memory, leading to an out-of-memory kill and denial of service. The cost is incurred during the first call to
getAllParts() or when reading content.Technical details include:
- Deep multipart nesting: The
MimeParserService::findContentBoundary()function andParserMimePartProxy::setEndBoundaryFound()function create a complexity of O(depth²). - Many sibling parts: The
PartChildrenContainer::add()function reindexes the entire array on every call, resulting in O(n²) complexity. - Unbounded header buffering: The
HeaderParserService::parse()function reads header lines without limits on count or total size, allowing a small message to consume gigabytes of memory.
Recommendations
For versions 2.0.0 through 3.0.5, upgrade to version 3.0.6 or later.
For versions 4.0.0 through 4.0.1, upgrade to version 4.0.2 or later.
Restrict exposure of the parser to untrusted input.
Run parsing under a constrained
memory limit and execution time limit.Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail-Mime-Parser