CVE-2026-42504
Awaiting Analysis
Awaiting Analysis - Queue
MIME Header Parsing Denial of Service in Go
Publication date: 2026-06-02
Last updated on: 2026-06-03
Assigner: Go Project
Description
Description
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| golang | go | to 1.25.11 (exc) |
| golang | go | From 1.26.0 (inc) to 1.26.4 (exc) |
| golang | go | 1.27 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-407 | An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached. |