Bug 2523719 (CVE-2026-55620)
| Summary: | CVE-2026-55620 eml_parser: eml_parser: Denial of Service via crafted email headers | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in eml_parser, a Python module designed for parsing email files. A remote attacker can exploit a vulnerability in how the module processes `Received:` headers containing deeply nested parentheses. By submitting specially crafted email files, an attacker can cause excessive CPU usage, leading to significant processing delays, system slowdowns, and potential service outages. This can impact synchronous gateways, sandboxes, and real-time email triage systems.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2524366, 2524367 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-25 18:31:59 UTC
|