Go net/mail 1.25.x-1.26.3: ParseAddress/Date CPU/Memory Exhaustion
CVE-2026-39820 Published on May 7, 2026
Quadratic string concatentation in consumeComment in net/mail
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
Vulnerability Analysis
CVE-2026-39820 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Privileges Required:
NONE
Confidentiality Impact:
NONE
Availability Impact:
HIGH
Weakness Type
Unchecked Input for Loop Condition
The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Products Associated with CVE-2026-39820
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-39820 are published in these products:
Affected Versions
Go standard library
net/mail:
-
Before 1.25.10
is affected.
-
Version 1.26.0-0 and below 1.26.3
is affected.
Logging for Red Hat OpenShift 6.4:
-
Version 1782405469 and below *
is unaffected.
Red Hat
OpenShift API for Data Protection 1.6:
-
Version 1784058822 and below *
is unaffected.
Red Hat Advanced Cluster Security 4.9:
-
Version 1783357116 and below *
is unaffected.
Red Hat Advanced Cluster Security for Kubernetes 4.10:
-
Version 1783357140 and below *
is unaffected.
Red Hat Developer Hub 1.10:
-
Version 1783447707 and below *
is unaffected.
Red Hat Developer Hub 1.9:
-
Version 1782767215 and below *
is unaffected.
Red Hat Hardened Images:
-
Version 1.25.11-2.hum1 and below *
is unaffected.
Red Hat Hardened Images:
-
Version 1.26.4-2.hum1 and below *
is unaffected.
Red Hat Migration Toolkit 1.8:
-
Version 1783953372 and below *
is unaffected.
Red Hat Migration Toolkit for Applications 8.2:
-
Version 1784211378 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1783544461 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.0:
-
Version 1782222217 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.0:
-
Version 1782223341 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.0:
-
Version 1782296193 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.0:
-
Version 1782222607 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.1:
-
Version 1782222163 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.1:
-
Version 1782223138 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.1:
-
Version 1782222394 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.1:
-
Version 1782222451 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.2:
-
Version 1782226178 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.2:
-
Version 1782224487 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.2:
-
Version 1782303211 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.2:
-
Version 1782224541 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.3:
-
Version 1782223045 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.3:
-
Version 1782222366 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.3:
-
Version 1782310747 and below *
is unaffected.
Red Hat OpenShift Service Mesh 3.3:
-
Version 1782222038 and below *
is unaffected.
Red Hat Quay 3.1:
-
Version 1783750447 and below *
is unaffected.
Red Hat Quay 3.12:
-
Version 1783751865 and below *
is unaffected.
-
Version 1784353904 and below *
is unaffected.
Red Hat Quay 3.15:
-
Version 1784351966 and below *
is unaffected.
Red Hat Quay 3.16:
-
Version 1783955846 and below *
is unaffected.
Red Hat Quay 3.9:
-
Version 1784125838 and below *
is unaffected.
Red Hat Trusted Artifact Signer 1.4:
-
Version 4-1.4.2 and below *
is unaffected.
Assisted Installer for Red Hat OpenShift Container Platform 2:
cert-manager Operator for Red Hat OpenShift:
Red Hat
Confidential Compute Attestation:
Red Hat
Confidential Compute Attestation:
Red Hat
Confidential Compute Attestation:
Red Hat
Cryostat 4:
Custom Metric Autoscaler operator for Red Hat Openshift:
External Secrets Operator for Red Hat OpenShift:
Red Hat
File Integrity Operator:
Red Hat
Gatekeeper 3:
Red Hat
Logical Volume Manager Storage:
Red Hat
Logical Volume Manager Storage:
Red Hat
Logical Volume Manager Storage:
Red Hat
Multiarch Tuning Operator:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Global Hub:
Red Hat
Multicluster Global Hub:
Red Hat
Network Observability Operator:
Red Hat
OpenShift API for Data Protection:
Red Hat
OpenShift Developer Tools and Services:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Pipelines:
Red Hat
OpenShift Serverless:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 3:
Power monitoring for Red Hat OpenShift:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Advanced Cluster Management for Kubernetes 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ceph Storage 5:
Red Hat Ceph Storage 6:
Red Hat Ceph Storage 9:
Red Hat Certification Program for Red Hat Enterprise Linux 9:
Red Hat Edge Manager 1:
Red Hat Edge Manager 1:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat Lightspeed for Runtimes Operator:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift Cluster Manager CLI:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat Openshift Data Foundation 4:
Red Hat Openshift Data Foundation 4:
Red Hat Openshift Data Foundation 4:
Red Hat Openshift Data Foundation 4:
Red Hat Openshift Data Foundation 4:
Red Hat OpenShift Dev Spaces:
Red Hat OpenShift Dev Spaces:
Red Hat OpenShift Dev Workspaces Operator:
Red Hat OpenShift distributed tracing 3:
Red Hat OpenShift for Windows Containers:
Red Hat OpenShift GitOps:
Red Hat OpenShift GitOps:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenShift Virtualization 4:
Red Hat OpenStack Platform 16.2:
Red Hat OpenStack Platform 17.1:
Red Hat OpenStack Platform 18.0:
Red Hat Quay 3:
Red Hat Satellite 6:
Red Hat Service Interconnect 1:
Red Hat Service Interconnect 2:
Red Hat Trusted Artifact Signer:
Red Hat
Security Profiles Operator:
Red Hat
Zero Trust Workload Identity Manager:
Red Hat
Zero Trust Workload Identity Manager - Tech Preview:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.