Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42504

Опубликовано: 02 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

A flaw was found in the Golang MIME (Multipurpose Internet Mail Extensions) package. A remote attacker could exploit this vulnerability by sending a maliciously-crafted MIME header containing many invalid encoded-words. This could lead to excessive CPU consumption, resulting in a Denial of Service (DoS) for the affected system.

Отчет

This is rated as an Important severity flaw. A remote attacker could trigger a Denial of Service by sending a crafted MIME header with numerous invalid encoded-words to an application utilizing the affected Golang MIME package. This could lead to excessive CPU consumption on the system processing the malformed header, impacting service availability.

Меры по смягчению последствий

To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-operator-bundleAffected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
File Integrity Operatorcompliance/openshift-compliance-operator-bundleAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2484204mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header

EPSS

Процентиль: 43%
0.0056
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVSS3: 7.5
nvd
около 2 месяцев назад

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVSS3: 7.5
msrc
около 2 месяцев назад

Quadratic complexity in WordDecoder.DecodeHeader in mime

CVSS3: 7.5
debian
около 2 месяцев назад

Decoding a maliciously-crafted MIME header containing many invalid enc ...

CVSS3: 7.5
github
около 2 месяцев назад

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

EPSS

Процентиль: 43%
0.0056
Низкий

7.5 High

CVSS3