Denial of Service in Go Programming Language's Email Parsing
CVE-2026-42499

Currently unrated

Key Information:

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-42499?

The Go programming language contains a vulnerability where pathological inputs can lead to a Denial of Service (DoS) condition during the processing of email addresses. This occurs specifically through the consumePhrase function while parsing input in accordance with RFC 5322, which is essential for ensuring valid email formatting. Exploiting this vulnerability may disrupt services that rely on proper email address handling, highlighting the importance of applying patches and updates to mitigate such risks.

Affected Version(s)

net/mail 0 < 1.25.10

net/mail 1.26.0-0 < 1.26.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.