Repository navigation
net/mail: ParseAddress: quadratic complexity in consumeComment #78566
Copy link
Copy link
Closed
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Security
Milestone
Description
Activity
@gopherbot please open backport issues for this security fix.
Backport issue(s) opened: #78567 (for 1.25), #78568 (for 1.26).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
Change https://go.dev/cl/763558 mentions this issue:
[release-branch.go1.25] net/mail: fix quadratic complexity in consumeCommentChange https://go.dev/cl/763800 mentions this issue:
[release-branch.go1.26] net/mail: fix quadratic complexity in consumeCommentRelated Issues
- net/mail: excessive CPU consumption in ParseAddress (CVE-2025-61725) #75680 (closed)
- encoding/pem: quadratic complexity when parsing some invalid inputs (CVE-2025-61723) #75676 (closed)
- net/textproto: excessive CPU consumption in Reader.ReadResponse (CVE-2025-61724) #75716 (closed)
(Emoji vote if this was helpful or unhelpful; more detailed feedback welcome in this discussion.)
- addedBugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.
on Apr 7, 2026 - addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.
on Apr 9, 2026 - added a commit that references this issue
on Jul 22, 2026 - added a commit that references this issue
on Sep 4, 2026
Metadata
Metadata
Assignees
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Security
Well-crafted inputs reaching ParseAddress, ParseAddressList,
and ParseDate were able to trigger excessive CPU exhaustion
and memory allocations.
This is CVE-2026-39820 and Go issue https://go.dev/issue/78566.
This was a PUBLIC track issue, tracked in http://b/500346169.