CVE-2026-82520

parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically processes incoming DMARC report emails without user interaction, an unauthenticated remote attacker can send a crafted email with a highly compressed attachment to the monitored mailbox, causing the parsedmarc process to allocate memory proportional to the uncompressed size and exhaust available RAM.

  • Published Sep 3, 2026
  • CVSS 8.7 high
  • 0.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-82520 at the National Vulnerability Database