CVE-2026-55619
Received Received - Intake

RecursionError in eml_parser Header Parsing via CFWS Comments

Vulnerability report for CVE-2026-55619, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: GitHub, Inc.

Description

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail headers. A deeply nested CFWS comment construct exhausts the standard-library recursive descent parser's call stack and raises RecursionError, which is not caught and therefore aborts parsing of the entire message. An attacker can disrupt SOC pipelines that process untrusted EML files, although callers already need to handle exceptions from malformed or pathological messages. This issue is fixed in version 3.0.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
govcert-lu eml_parser to 3.0.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1124 The code contains a callable or other code grouping in which the nesting / branching is too deep.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55619 is a Denial of Service (DoS) vulnerability in the eml_parser library affecting versions before 3.0.2. It occurs when email headers contain deeply nested CFWS comment constructs that exhaust the recursive descent parser's call stack, causing a RecursionError. Since eml_parser does not catch this exception, it stops parsing the entire email message.

Detection Guidance

Monitor for RecursionError exceptions in logs when processing EML files with eml_parser versions prior to 3.0.2. Check for crashes in SOC pipelines handling untrusted emails. Use try/except blocks around eml_parser.decode_email calls to catch exceptions.

Impact Analysis

An attacker can craft malicious email files to trigger this vulnerability, disrupting systems that rely on eml_parser for processing untrusted EML files. This is particularly risky for SOC pipelines handling incoming emails. The impact is limited to service disruption as no data is compromised.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by disrupting SOC pipelines that process untrusted EML files. A Denial of Service (DoS) attack via crafted emails may cause systems to fail in handling critical data, potentially leading to delays in processing or loss of access to sensitive information. However, the vulnerability itself does not directly violate these regulations but may contribute to operational failures that could affect compliance.

Mitigation Strategies

Upgrade eml_parser to version 3.0.2 or later. Wrap eml_parser.decode_email or decode_email_bytes calls in try/except blocks to handle exceptions gracefully. Avoid processing deeply nested or malformed email headers until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart