CVE-2026-55619: CWE-770: Allocation of Resources Without Limits or Throttling in GOVCERT-LU eml_parser
Description
CVE-2026-55619 is a medium severity vulnerability in the GOVCERT-LU eml_parser Python module prior to version 3.0.2. The issue arises from the HeaderParser.header_fetch_parse function using email.utils.getaddresses() to parse email headers. A deeply nested CFWS comment construct can cause the standard library's recursive parser to exhaust the call stack, raising an uncaught RecursionError and aborting the parsing of the entire message. This can disrupt security operations center (SOC) pipelines processing untrusted EML files. The vulnerability is fixed in eml_parser version 3.0.2.
CVSS v3.1
Score 5.3medium
Affected software
GOVCERT-LU
eml_parser
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The eml_parser Python module, used for parsing EML files, contained a vulnerability in versions before 3.0.2 where the header parsing function relied on email.utils.getaddresses(). This function's recursive descent parser can be overwhelmed by deeply nested CFWS comments, causing a RecursionError that is not handled, leading to aborted parsing of the entire email message. This resource exhaustion vulnerability can disrupt automated processing pipelines that handle untrusted email files. The issue is addressed by updating to version 3.0.2 of eml_parser.
Potential Impact
An attacker can craft malicious EML files with deeply nested comments that trigger a RecursionError during parsing, causing the parser to abort processing. This results in denial of service to systems relying on eml_parser for email analysis, such as SOC pipelines. There is no direct confidentiality or integrity impact reported. The vulnerability affects availability by disrupting email parsing workflows.
Mitigation Recommendations
Upgrade eml_parser to version 3.0.2 or later, where this issue is fixed. Callers should continue to handle exceptions from malformed or pathological messages as a best practice. No other specific mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:31:22.446Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8de143acd9273b4991a18d
Added to database: 08/25/2026, 18:38:59 UTC
Last enriched: 09/10/2026, 17:53:41 UTC
Last updated: 10/08/2026, 18:48:46 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.