Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42499

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

A flaw was found in the net/mail package within the Go standard library. A remote attacker could provide specially crafted, pathological email addresses. When these malformed email addresses are parsed by the consumePhrase function, it can lead to excessive resource consumption due to quadratic string concatenation, resulting in a Denial of Service (DoS) condition.

Отчет

This is an Important denial of service vulnerability in the net/mail package of the Go standard library. A remote attacker can exploit this flaw by sending specially crafted email addresses, leading to excessive resource consumption and a denial of service in Go applications that parse email addresses using the affected library.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
File Integrity Operatorcompliance/openshift-compliance-operator-bundleAffected
Gatekeeper 3gatekeeper/gatekeeper-rhel9-operatorUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1046
https://bugzilla.redhat.com/show_bug.cgi?id=2467809net/mail: golang: net/mail: Denial of Service via pathological email address parsing

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

CVSS3: 7.5
nvd
3 месяца назад

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

msrc
3 месяца назад

Quadratic string concatenation in consumePhrase in net/mail

CVSS3: 7.5
debian
3 месяца назад

Pathological inputs could cause DoS through consumePhrase when parsing ...

CVSS3: 7.5
github
3 месяца назад

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

7.5 High

CVSS3