Repository navigation
net/mail: quadratic string concatenation in consumePhrase #78987
Copy link
Copy link
Closed
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Security
Description
Activity
- addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.
on Apr 28, 2026 Related Issues
- net/mail: ParseAddress: quadratic complexity in consumeComment #78566
- net/mail: excessive CPU consumption in ParseAddress (CVE-2025-61725) #75680 (closed)
(Emoji vote if this was helpful or unhelpful; more detailed feedback welcome in this discussion.)
Change https://go.dev/cl/771520 mentions this issue:
net/mail: fix quadratic consumePhrase behavior- pinned this issue
on Apr 28, 2026 - unpinned this issue
on Apr 28, 2026 @gopherbot please open backport issues for this security fix
Backport issue(s) opened: #79003 (for 1.25), #79004 (for 1.26).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
- added a commit that references this issue
on Apr 29, 2026 Change https://go.dev/cl/772121 mentions this issue:
[release-branch.go1.26] net/mail: fix quadratic consumePhrase behaviorChange https://go.dev/cl/772120 mentions this issue:
[release-branch.go1.25] net/mail: fix quadratic consumePhrase behavior- added a commit that references this issue
on Jul 22, 2026 - added a commit that references this issue
on Sep 4, 2026
Metadata
Metadata
Assignees
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Security
Pathological inputs could cause DoS through consumePhrase
when parsing an email address according to RFC 5322.
This is CVE-2026-42499 and Go issue https://go.dev/issue/78987.
This was a PUBLIC track issue, tracked in http://b/502123043.