ProtonMail Web Client Regular Expression Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the ProtonMail Web Client, specifically in versions prior to 3.16.60. This vulnerability arises from a regular expression that can be exploited to cause exponential backtracking, leading to a significant performance degradation. The issue occurs in the Autocrypt public key extraction process, where the regular expression improperly handles certain input patterns, allowing for crafted strings to disrupt normal operation.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, where the application becomes unresponsive or significantly slower due to the inefficient processing of regular expressions.

Reproduction

The vulnerability can be reproduced by using a specially crafted string that exploits the regular expression used to parse Autocrypt headers. This can be done by sending an email that includes an Autocrypt header with a 'keydata' attribute containing a base64-encoded string. The ProtonMail Web Client will then decode this header, triggering the regular expression denial-of-service vulnerability.

Remediation

Users can update to ProtonMail Web Client version 3.16.60 or later to address this vulnerability.

Added: May 15, 2026, 9:23 AM
Updated: May 15, 2026, 9:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.