目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-61816— zbateson/mail-mime-parser 解析未信任MIME时存在资源消耗失控漏洞

一分钟漏洞结论

影响对象
zbateson mail-mime-parser
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

漏洞描述翻译: 是一个替代 PHP 的 函数和 Pear 库的邮件 MIME 解析器,用于读取符合 Internet Message Format RFC 822 标准的电子邮件消息。在版本 2.0.0 至 3.0.6 之前,以及 4.0.2 之前的版本中,存在一个不受控的资源消耗 / 算法复杂性漏洞(CWE-400),任何使用该库解析不受信任电子邮件的应用程序都会受到影响。三个独立的解析路径的成本随输入规模呈超线性增长,因此,仅对调用方设置字节大小限制无法有效控制实际执行的工作量。 一个精心构造的、大小低于 2

CVSS 7.5 · High EPSS 0.39% · P31
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-61816 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
来源: CVE Program / CVE List V5
Vulnerability Description
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects any application that parses untrusted email with this library. Three independent parsing paths are super-linear in cost, so a byte-size cap on the caller side does **not** bound the work done. A crafted message under 2 MB can consume seconds of CPU or hundreds of megabytes to multiple gigabytes of memory (leading to an out-of-memory kill), enabling denial of service. The parse is lazy, but the cost is paid on the first `getAllParts()` or content read. This is fxed in 4.0.2 and 3.0.6. The fixes add configurable limits on multipart nesting depth and on header count / total header size (recording a parse error past the threshold rather than throwing), and change sibling append to O(n). Users should upgrade to one of these (or later) versions. Versions 2.x are also affected but are end-of-life and will not receive patches; users on those lines should upgrade to a fixed release. (Versions prior to 2.0 used a different parser and are not affected by all three paths.) These costs are super-linear, so an input byte-size cap alone does not bound them. Until upgrading, restrict exposure of the parser to untrusted input, and run parsing under a constrained memory_limit and execution time limit so a malicious message fails its own request rather than exhausting the host.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zbateson mail-mime-parser >= 2.0.0, < 3.0.6 -

二、漏洞 CVE-2026-61816 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-61816 的情报信息

请登录查看更多情报信息。

CVE-2026-61816 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61816

暂无评论


发表评论