HomeDefault status
unaffected
Any version before 1.25.11
affected
1.26.0-0 (semver) before 1.26.4
affected
Description
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
Problem types
CWE-407: Inefficient Algorithmic Complexity
Product status
Any version before 1.25.11
1.26.0-0 (semver) before 1.26.4
Credits
p4p3r (https://hackerone.com/p4p3r_hak)
References
groups.google.com/g/golang-announce/c/tKs3rmcBcKw