Multiple security vulnerabilities have been identified in zbateson/mail-mime-parser, a package that handles email MIME messages. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to denial-of-service (DoS) or injection attacks. Affected versions 3.0.5 and below are vulnerable.
CVE-2026-61816 (CVSS 7.5 — High): zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME, allowing an attacker to cause a denial-of-service condition via CPU or memory exhaustion.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in zbateson/mail-mime-parser, a package that handles email MIME messages. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to denial-of-service (DoS) or injection attacks. Affected versions 3.0.5 and below are vulnerable.
CVE-2026-61816 (CVSS 7.5 — High): zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME, allowing an attacker to cause a denial-of-service condition via CPU or memory exhaustion.[emaillocker id="1283"]
CVE-2026-61815: zbateson/mail-mime-parser has CRLF header injection via attachment filename, enabling an attacker to inject malicious headers into email messages.
These vulnerabilities collectively present a significant risk to systems relying on zbateson/mail-mime-parser for email processing.
We recommend you to update mail-mime-parser to version 4.0.2.
The following reports contain further technical details:
[/emaillocker]