CVE-2026-55620General

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fix-point loop whose running time is quadratic in the nesting depth. A single Received: header with 5,000 nested parentheses causes approximately 1.3 seconds of CPU saturation per parsed message, and doubling the nesting depth approximately quadruples the running time. An attacker can submit relatively small EML files that consume multiple seconds of processing time, causing worker latency, queue backpressure, and possible service-level outages in synchronous gateways, sandboxes, and real-time triage pipelines. This issue is fixed in version 3.0.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-1124

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 208-25
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55620 eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_… https://www.cve.org/CVERecord?id=CVE-2026-55620 ----- Traducción: CVE-2026-55620 eml… https://infoflow.cloud`

    Post summary

    The tweet simply references CVE-2026-55620 and links to its record, providing no additional technical or exploit information.

    0000040
    102 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-55620 eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_… https://www.cve.org/CVERecord?id=CVE-2026-55620

    Post summary

    The post briefly mentions CVE‑2026‑55620 as relating to an eml_parser Python module version prior to 3.0.2, without providing technical details, exploitation evidence, or remediation guidance.

    00000883
    58.0K followersView on X

Explore more