Threat Advisory

zbateson/mail-mime-parser has uncontrolled resource consumption parsing untrusted MIME

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in zbateson/mail-mime-parser, a package that handles email MIME messages. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to denial-of-service (DoS) or injection attacks. Affected versions 3.0.5 and below are vulnerable.

CVE-2026-61816 (CVSS 7.5 — High): zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME, allowing an attacker to cause a denial-of-service condition via CPU or memory exhaustion.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in zbateson/mail-mime-parser, a package that handles email MIME messages. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to denial-of-service (DoS) or injection attacks. Affected versions 3.0.5 and below are vulnerable.

CVE-2026-61816 (CVSS 7.5 — High): zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME, allowing an attacker to cause a denial-of-service condition via CPU or memory exhaustion.[emaillocker id="1283"]

CVE-2026-61815: zbateson/mail-mime-parser has CRLF header injection via attachment filename, enabling an attacker to inject malicious headers into email messages.

These vulnerabilities collectively present a significant risk to systems relying on zbateson/mail-mime-parser for email processing.

RECOMMENDATION:

We recommend you to update mail-mime-parser to version 4.0.2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu