Threats Tagged 'cwe-1124'
View all threats tagged with 'cwe-1124'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1124'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-55620 is a high-severity vulnerability in the GOVCERT-LU eml_parser Python module prior to version 3.0.2. The flaw involves a regex-based fix-point loop in the function eml_parser.routing.noparenthesis that removes parenthesized comments from Received: headers. This loop has quadratic time complexity relative to the nesting depth of parentheses, causing excessive CPU consumption when processing emails with deeply nested parentheses. An attacker can exploit this by submitting crafted EML files with deeply nested parentheses, leading to significant processing delays and potential denial of service in synchronous email processing systems. The issue is fixed in version 3.0.2. No official patch advisory or exploit reports are currently available. Join the discussion | CVE Database V5 | 08/25/2026, 18:26:54 UTC Added: 08/25/2026, 18:38:59 UTC |
0 CVE-2026-55619 is a medium severity vulnerability in the GOVCERT-LU eml_parser Python module prior to version 3.0.2. The issue arises from the HeaderParser.header_fetch_parse function using email.utils.getaddresses() to parse email headers. A deeply nested CFWS comment construct can cause the standard library's recursive parser to exhaust the call stack, raising an uncaught RecursionError and aborting the parsing of the entire message. This can disrupt security operations center (SOC) pipelines processing untrusted EML files. The vulnerability is fixed in eml_parser version 3.0.2. Join the discussion | CVE Database V5 | 08/25/2026, 18:24:29 UTC Added: 08/25/2026, 18:38:59 UTC |
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1. Join the discussion | CVE Database V5 | 06/26/2026, 17:29:14 UTC Added: 06/26/2026, 18:12:30 UTC |
Showing 1 to 3 of 3 results