Skip to main content

Threats Tagged 'cwe-1124'

View all threats tagged with 'cwe-1124'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1124

Threats Tagged 'cwe-1124'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-55620 is a high-severity vulnerability in the GOVCERT-LU eml_parser Python module prior to version 3.0.2. The flaw involves a regex-based fix-point loop in the function eml_parser.routing.noparenthesis that removes parenthesized comments from Received: headers. This loop has quadratic time complexity relative to the nesting depth of parentheses, causing excessive CPU consumption when processing emails with deeply nested parentheses. An attacker can exploit this by submitting crafted EML files with deeply nested parentheses, leading to significant processing delays and potential denial of service in synchronous email processing systems. The issue is fixed in version 3.0.2. No official patch advisory or exploit reports are currently available.

Join the discussion

CVE-2026-55619 is a medium severity vulnerability in the GOVCERT-LU eml_parser Python module prior to version 3.0.2. The issue arises from the HeaderParser.header_fetch_parse function using email.utils.getaddresses() to parse email headers. A deeply nested CFWS comment construct can cause the standard library's recursive parser to exhaust the call stack, raising an uncaught RecursionError and aborting the parsing of the entire message. This can disrupt security operations center (SOC) pipelines processing untrusted EML files. The vulnerability is fixed in eml_parser version 3.0.2.

Join the discussion

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cwe-1124
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses