Go standard library net/mail

3 known vulnerabilities in Go standard library net/mail, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-42499 CVSS 7.5 high Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
  • CVE-2026-39820 CVSS 7.5 high Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory…
  • CVE-2025-61725 CVSS 7.5 high The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large…