Skip to content

net/mail: quadratic string concatenation in consumePhrase #78987

@thatnealpatel

Description

@thatnealpatel

Pathological inputs could cause DoS through consumePhrase
when parsing an email address according to RFC 5322.

This is CVE-2026-42499 and Go issue https://go.dev/issue/78987.


This was a PUBLIC track issue, tracked in http://b/502123043.

Metadata

Metadata

Assignees

Labels

BugReportIssues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.Security

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions