Denial-of-Service Vulnerability in Stalwart Mail Server by Stalwart Labs
CVE-2026-26312
What is CVE-2026-26312?
A denial-of-service vulnerability exists in Stalwart Mail Server versions 0.13.0 through 0.15.4. This flaw can be exploited when a specially crafted email containing malformed nested 'message/rfc822' MIME parts is accessed via IMAP or JMAP. The malformed structure leads to excessive CPU and memory consumption due to cyclical references generated by the 'mail-parser' crate, which Stalwart Mail Server follows indefinitely, potentially resulting in an out-of-memory condition and server crash. Users are advised to upgrade to version 0.15.5 or higher, which includes a patch for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
stalwart >= 0.13.0, < 0.15.5
