CVE-2026-42504

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

  • Published Jun 2, 2026
  • CVSS 7.5 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-42504 at the National Vulnerability Database