Skip to content

net/mail: ParseAddress: quadratic complexity in consumeComment #78566

@neild

Description

@neild

Well-crafted inputs reaching ParseAddress, ParseAddressList,
and ParseDate were able to trigger excessive CPU exhaustion
and memory allocations.

This is CVE-2026-39820 and Go issue https://go.dev/issue/78566.


This was a PUBLIC track issue, tracked in http://b/500346169.

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugReportIssues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.Security

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions