Bug 2523724 (CVE-2026-55618)
| Summary: | CVE-2026-55618 eml_parser: eml_parser: Security bypass due to incorrect URL validation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in eml_parser, a Python module for parsing email files. The `clean_found_uri` function incorrectly validates Uniform Resource Locator (URL) strings by processing them before unescaping HTML entities. This allows a remote attacker to craft malicious URLs using HTML entities that are then improperly rejected and omitted from extracted URL lists. Consequently, email security gateways and Security Operations Center (SOC) pipelines may fail to detect and inspect these hidden malicious links, leading to a bypass of security measures and potential information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2524362, 2524363 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-25 18:32:29 UTC
|