Quadratic string concatenation in consumePhrase in net/mail
Summary
| CVE | CVE-2026-42499 |
|---|---|
| State | PUBLISHED |
| Assigner | Go |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-07 20:16:44 UTC |
| Updated | 2026-08-20 13:18:32 UTC |
| Description | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.000230000 probability, percentile 0.065470000 (date 2026-05-12)
Problem Types: NVD-CWE-noinfo | CWE-1046 | CWE-407: Inefficient Algorithmic Complexity | CWE-1046 Creation of Immutable Text Using String Concatenation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:57194 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36797 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54284 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:41928 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43038 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:41031 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:50300 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43692 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54531 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54274 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:47952 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:42644 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36754 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| go.dev/issue/78987 | [email protected] | go.dev | Issue Tracking |
| go.dev/cl/771520 | [email protected] | go.dev | Patch |
| access.redhat.com/errata/RHSA-2026:54286 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54283 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:43052 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:34364 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:33123 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:50843 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-42499 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54555 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54583 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:51033 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36319 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| pkg.go.dev/vuln/GO-2026-4977 | [email protected] | pkg.go.dev | Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:40262 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:17713 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54287 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:33120 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| groups.google.com/g/golang-announce/c/qcCIEXso47M | [email protected] | groups.google.com | Release Notes |
| access.redhat.com/errata/RHSA-2026:42146 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36625 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:33142 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54285 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:17714 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:41066 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54602 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:54552 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:33150 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:42796 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:56340 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:33574 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-05-07T20:00:51.685Z | Reported to Red Hat. |
| ADP | 2026-05-07T19:41:18.615Z | Made public. |
Solutions
ADP: RHSA-2026:54552: Red Hat OpenShift Container Platform 4.19
ADP: RHSA-2026:54531: Cert Manager support for Red Hat OpenShift release 1.19
ADP: RHSA-2026:47952: Logging Subsystem for Red Hat OpenShift 6.2
ADP: RHSA-2026:56340: Logging Subsystem for Red Hat OpenShift 6.5
ADP: RHSA-2026:50843: Logging Subsystem for Red Hat OpenShift 6
ADP: RHSA-2026:34364: Logging for Red Hat OpenShift 6.4
ADP: RHSA-2026:51033: OpenShift API for Data Protection 1.3
ADP: RHSA-2026:43692: OpenShift API for Data Protection 1.6
ADP: RHSA-2026:36319: Red Hat Advanced Cluster Security 4.9
ADP: RHSA-2026:36625: Red Hat Advanced Cluster Security for Kubernetes 4.10
ADP: RHSA-2026:36754: Red Hat Developer Hub 1.10
ADP: RHSA-2026:33574: Red Hat Developer Hub 1.9
ADP: RHSA-2026:17713: Red Hat Hardened Images
ADP: RHSA-2026:17714: Red Hat Hardened Images
ADP: RHSA-2026:41928: Red Hat Migration Toolkit 1.8
ADP: RHSA-2026:50300: Red Hat Migration Toolkit for Applications 8.1
ADP: RHSA-2026:43038: Red Hat Migration Toolkit for Applications 8.2
ADP: RHSA-2026:42644: Red Hat OpenShift AI 2.25
ADP: RHSA-2026:54555: Red Hat OpenShift Container Platform 4.19
ADP: RHSA-2026:54583: Red Hat OpenShift Container Platform 4.20
ADP: RHSA-2026:54602: Red Hat OpenShift Container Platform 4.21
ADP: RHSA-2026:33120: Red Hat OpenShift Service Mesh 3.0
ADP: RHSA-2026:33123: Red Hat OpenShift Service Mesh 3.1
ADP: RHSA-2026:33142: Red Hat OpenShift Service Mesh 3.2
ADP: RHSA-2026:33150: Red Hat OpenShift Service Mesh 3.3
ADP: RHSA-2026:54287: Red Hat OpenShift Workload Availability 0.12
ADP: RHSA-2026:54284: Red Hat OpenShift Workload Availability 0.13
ADP: RHSA-2026:54286: Red Hat OpenShift Workload Availability 0.3
ADP: RHSA-2026:54285: Red Hat OpenShift Workload Availability 0.7
ADP: RHSA-2026:54274: Red Hat OpenShift Workload Availability 0.8
ADP: RHSA-2026:54283: Red Hat OpenShift Workload Availability 5.7
ADP: RHSA-2026:42146: Red Hat Quay 3.12
ADP: RHSA-2026:43052: Red Hat Quay 3.12
ADP: RHSA-2026:42796: Red Hat Quay 3.15
ADP: RHSA-2026:41066: Red Hat Quay 3.16
ADP: RHSA-2026:41031: Red Hat Quay 3.1
ADP: RHSA-2026:40262: Red Hat Quay 3.9
ADP: RHSA-2026:36797: Red Hat Trusted Artifact Signer 1.4
ADP: RHSA-2026:57194: multicluster engine for Kubernetes 2.11
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.