CVE-2026-39820: CWE-407: Inefficient Algorithmic Complexity in Go standard library net/mail
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-39820) in the Go standard library net/mail package involves inefficient algorithmic complexity (CWE-407) and unchecked input for loop condition (CWE-606). When applications call ParseAddress, ParseAddressList, or ParseDate with specially crafted inputs, it can trigger excessive CPU exhaustion and memory allocations, resulting in denial of service. The issue is confirmed by Red Hat and scored with a CVSS v3.1 base score of 7.5 (high severity) with no confidentiality or integrity impact but high availability impact. Red Hat advisories indicate no current patch or fix meeting their criteria is available, and mitigation options are limited. The vulnerability affects specific Go versions including 1.26.0-0 and 0 as stated.
Potential Impact
The vulnerability allows an attacker to cause denial of service by exhausting CPU and memory resources in applications using the affected Go net/mail functions. This can lead to service unavailability for applications processing untrusted email inputs. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
According to the Red Hat advisory, no official fix or patch currently meets their criteria for deployment and stability. Users should monitor vendor advisories for updates and consider upgrading to supported versions once fixes become available. In the meantime, mitigating exposure by limiting or validating untrusted inputs to the affected functions may reduce risk, although no specific mitigation is officially recommended.
CVE-2026-39820: CWE-407: Inefficient Algorithmic Complexity in Go standard library net/mail
Description
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVSS v3.1
Score 7.5high
Affected software
Go standard library
net/mail
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-39820) in the Go standard library net/mail package involves inefficient algorithmic complexity (CWE-407) and unchecked input for loop condition (CWE-606). When applications call ParseAddress, ParseAddressList, or ParseDate with specially crafted inputs, it can trigger excessive CPU exhaustion and memory allocations, resulting in denial of service. The issue is confirmed by Red Hat and scored with a CVSS v3.1 base score of 7.5 (high severity) with no confidentiality or integrity impact but high availability impact. Red Hat advisories indicate no current patch or fix meeting their criteria is available, and mitigation options are limited. The vulnerability affects specific Go versions including 1.26.0-0 and 0 as stated.
Potential Impact
The vulnerability allows an attacker to cause denial of service by exhausting CPU and memory resources in applications using the affected Go net/mail functions. This can lead to service unavailability for applications processing untrusted email inputs. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
According to the Red Hat advisory, no official fix or patch currently meets their criteria for deployment and stability. Users should monitor vendor advisories for updates and consider upgrading to supported versions once fixes become available. In the meantime, mitigating exposure by limiting or validating untrusted inputs to the affected functions may reduce risk, although no specific mitigation is officially recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-04-07T18:13:03.526Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-39820","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33120","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33123","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33142","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33150","vendor":"Red Hat"}]
Threat ID: 69fcf0c1cbff5d86102bd5c5
Added to database: 05/07/2026, 20:06:25 UTC
Last enriched: 08/14/2026, 16:54:16 UTC
Last updated: 09/12/2026, 22:13:35 UTC
Views: 319
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.