Go net/mail Package Excessive Resource Consumption Vulnerability
Vulnerability
A vulnerability exists in the Go programming language's net/mail package, specifically in versions prior to 1.25.10 and between 1.26.0 and 1.26.3. This vulnerability allows well-crafted inputs to the ParseAddress, ParseAddressList, and ParseDate functions to cause excessive CPU usage and memory allocation, leading to potential denial-of-service conditions.
Impact
Exploitation of this vulnerability can cause excessive CPU exhaustion and memory allocations, leading to potential denial-of-service conditions.
Remediation
Users can upgrade to Go versions 1.25.10 or 1.26.3 to address this vulnerability.
Added: May 7, 2026, 8:59 PM
Updated: May 7, 2026, 8:59 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
8.1remediation
0.0relevance
7.7threat
3.2urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
