VDB
Sign up
HIGH7.5

GHSA-g7gc-gmgp-wgqg

eml_parser vulnerable to DoS via deeply nested parens in Received headers

Quick fix

GHSA-g7gc-gmgp-wgqg — eml-parser: upgrade to the fixed version with the command below.

pip install --upgrade 'eml-parser>=3.0.2'

Details

### Summary

`eml_parser` strips parenthesised CFWS comments from `Received:` headers using a regex-based fix-point loop. The loop has quadratic time complexity in the number of nested parens. A single `Received:` header containing 5,000 nested parens causes ~1.3 seconds of CPU saturation per parsed message; runtime quadruples per doubling of nesting depth.

### Impact

This represents a CPU exhaustion DoS in any pipeline that processes attacker-supplied EML files. An attacker can create relatively small EML files that will take multiple seconds to parse.

This is particularly problematic for synchronous email-processing pipelines (gateways, sandboxes, real-time triage) where worker latency directly translates to queue backpressure and possible service-level outages.

### Patches

Since version 3.0.2, `eml_parser` uses a linear-time algorithm to remove the comments from `Received:` headers.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/eml-parser
Introduced in: 0Fixed in: 3.0.2
Fixpip install --upgrade 'eml-parser>=3.0.2'

References