Go net/mail Package Excessive Resource Consumption Vulnerability

Vulnerability

A vulnerability exists in the Go programming language's net/mail package, specifically in versions prior to 1.25.10 and between 1.26.0 and 1.26.3. This vulnerability allows well-crafted inputs to the ParseAddress, ParseAddressList, and ParseDate functions to cause excessive CPU usage and memory allocation, leading to potential denial-of-service conditions.

Impact

Exploitation of this vulnerability can cause excessive CPU exhaustion and memory allocations, leading to potential denial-of-service conditions.

Remediation

Users can upgrade to Go versions 1.25.10 or 1.26.3 to address this vulnerability.

Added: May 7, 2026, 8:59 PM
Updated: May 7, 2026, 8:59 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
7.7
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.