Description
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail headers. A deeply nested CFWS comment construct exhausts the standard-library recursive descent parser's call stack and raises RecursionError, which is not caught and therefore aborts parsing of the entire message. An attacker can disrupt SOC pipelines that process untrusted EML files, although callers already need to handle exceptions from malformed or pathological messages. This issue is fixed in version 3.0.2.
Published: 2026-08-25
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a recursive descent parser invoked by eml_parser.parser.HeaderParser.header_fetch_parse. When an e‑mail header contains a deeply nested CFWS comment construct, the standard‑library parser exhausts its call stack and throws a RecursionError that is not handled, causing the entire message parsing to abort. The result is a denial of ability to process legitimate or innocuous EML files, potentially crippling downstream security operations or data ingestion pipelines. The weakness is a classic input validation failure (CWE‑1124) combined with a stack overflow condition (CWE‑770).

Affected Systems

The flaw affects the GOVCERT‑LU eml_parser package in all releases older than v3.0.2. Version 3.0.2 and later include a fix that sanitizes or guards against the recursive descent recursion exception. No other products are directly impacted by this issue.

Risk and Exploitability

The CVSS score of 5.3 classifies the flaw as medium severity due to its limited scope and need to supply a crafted EML file. EPSS is not available, but the lack of a publicly available exploit and the requirement for a malformed input suggest a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. An attacker can trigger the denial of service by sending maliciously crafted e‑mail messages containing nested parentheses or CFWS comments to any system that parses EML files using this library. Proper exception handling or the availability of the patched library mitigates the risk.

Generated by OpenCVE AI on August 25, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply eml_parser v3.0.2 or later to ensure the recursion guard is in place
  • Configure SOC pipelines to catch RecursionError exceptions during EML parsing and fail gracefully instead of aborting
  • Implement input validation or header sanitization to reject or truncate overly nested CFWS comments before parsing

Generated by OpenCVE AI on August 25, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m66c-fw79-6359 eml_parser has parser DoS via deeply nested parentheses in e-mail headers
History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Govcert-lu
Govcert-lu eml Parser
Vendors & Products Govcert-lu
Govcert-lu eml Parser

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail headers. A deeply nested CFWS comment construct exhausts the standard-library recursive descent parser's call stack and raises RecursionError, which is not caught and therefore aborts parsing of the entire message. An attacker can disrupt SOC pipelines that process untrusted EML files, although callers already need to handle exceptions from malformed or pathological messages. This issue is fixed in version 3.0.2.
Title eml_parser: Parser DoS via deeply nested parentheses in e-mail headers
Weaknesses CWE-1124
CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Govcert-lu Eml Parser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-25T19:20:15.362Z

Reserved: 2026-06-16T23:31:22.446Z

Link: CVE-2026-55619

cve-icon Vulnrichment

Updated: 2026-08-25T19:19:02.650Z

cve-icon NVD

Status : Received

Published: 2026-08-25T19:16:50.477

Modified: 2026-08-25T20:16:57.673

Link: CVE-2026-55619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:15:04Z

Weaknesses
  • CWE-1124

    Excessively Deep Nesting

  • CWE-770

    Allocation of Resources Without Limits or Throttling