Medium · 4.9 PHP packages GHSA-f6v3-2qmr-vfjx CVE-2026-61816 PKSA-r8x8-972m-nrc1 GHSA-36h5-qg4p-q2qf
Two Vulnerabilities in zbateson/mail-mime-parser: Denial-of-Service and CRLF Header Injection
The PHP library zbateson/mail-mime-parser contains two separate vulnerabilities: an algorithmic-complexity denial-of-service issue (CVE-2026-61816) and a CRLF header injection flaw via attachment filenames (CVE-2026-61815). Both are fixed in versions 3.0.6 and 4.0.2.
AI summary
The Composer package zbateson/mail-mime-parser, a PHP library for parsing RFC 822 email messages, is affected by two distinct, independently reported vulnerabilities. One allows an attacker to cause excessive CPU or memory consumption through a specially crafted message, and the other allows injection of forged email headers via attachment filenames. Both issues have been fixed by the maintainers in versions 3.0.6 and 4.0.2.
What happened
Two vulnerabilities were disclosed in zbateson/mail-mime-parser, a PHP library used to parse MIME email messages. CVE-2026-61816 is an uncontrolled resource consumption issue (CWE-400): three independent parsing paths in the library have super-linear algorithmic cost, meaning a crafted message under 2 MB can cause seconds of CPU time or hundreds of megabytes to multiple gigabytes of memory use, potentially triggering an out-of-memory kill. A simple byte-size limit on the input does not prevent this because the cost does not scale linearly with input size. CVE-2026-61815 is a CRLF header injection issue (CWE-93): attachment filenames are inserted into Content-Type and Content-Disposition header values without stripping carriage-return/line-feed characters. A filename containing CR/LF sequences can inject additional, attacker-controlled header lines into an outgoing message — for example a forged Bcc header that silently copies the message to another recipient.
Technical cause
For CVE-2026-61816, the parser performs lazy parsing, but the super-linear cost is paid the first time getAllParts() is called or content is read. Three separate code paths exhibit this super-linear behavior, so capping the byte size of input email does not bound the resource cost. For CVE-2026-61815, attachment filenames — including those taken directly from a previously parsed, untrusted inbound email — are interpolated into Content-Type and Content-Disposition header values without sanitizing CR/LF characters, allowing the filename to break out of its intended header field and introduce new header lines.
Why it matters
Any application that parses untrusted email using this library is exposed to the denial-of-service issue; an attacker needs only to send a small, specially crafted message. Applications that re-attach or re-send a filename obtained from a parsed inbound message (for example, forwarding or re-sending attachments) are exposed to the CRLF injection issue, which could be used to forge additional headers such as a hidden Bcc recipient, silently exfiltrating a copy of the outgoing message.
Affected versions
CVE-2026-61816 (resource consumption): affects versions starting at 2.0.0 and prior to 3.0.6, and versions starting at 4.0.0 and prior to 4.0.2. Versions prior to 2.0.0 used a different parser and are not affected by all three vulnerable code paths. CVE-2026-61815 (CRLF injection): affects versions prior to 3.0.6 and versions starting at 4.0.0 and prior to 4.0.2. For both issues, the 2.x line (and for CRLF injection, also the 1.x line) is affected but is end-of-life and will not receive a patch; users on these lines must upgrade to a fixed, supported version.
Fixes and mitigation
Both vulnerabilities are fixed in versions 3.0.6 and 4.0.2. For the resource consumption issue, the fix adds configurable limits on multipart nesting depth and on header count/total header size (recording a parse error past the threshold instead of throwing), and changes sibling append handling to linear (O(n)) complexity. For the CRLF injection issue, the fix sanitizes attachment filenames before they are placed into header values. Users on end-of-life 1.x or 2.x versions will not receive patches and should upgrade to a currently maintained, fixed release.
Recommended action
Upgrade zbateson/mail-mime-parser to version 3.0.6 or 4.0.2 (or later) as soon as possible. If upgrading immediately is not possible: for the resource consumption issue, restrict exposure of the parser to untrusted input and run parsing under a constrained memory_limit and execution time limit so a malicious message fails its own request rather than exhausting the host. For the CRLF injection issue, strip CR and LF characters from any filename before passing it to attachment APIs, and from the result of getFilename() before reusing it in a constructed message, for example using preg_replace('/[\r\n]+/', ' ', $filename).
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
CVE-2026-61816 has a CVSS base score of 7.5 (Network attack vector, low complexity, no privileges or user interaction required, high availability impact). CVE-2026-61815 has a CVSS base score of 7.2 (Network attack vector, low complexity, no privileges or user interaction required, changed scope, low confidentiality and integrity impact). Patchwire scores of 4.9 and 4.8 respectively reflect that both are remotely exploitable without authentication or user interaction and fixes are available, but there is no evidence of known exploitation, public exploit code, or elevated EPSS likelihood for either issue.
Affected versions
- zbateson/mail-mime-parser >= 4.0.0, < 4.0.2
- vulnerable
- zbateson/mail-mime-parser >=4.0.0,<4.0.2|>=2.0.0,<3.0.6
- vulnerable
- ≥ 3.0.6
- patched
- ≥ 4.0.2
- patched
- zbateson/mail-mime-parser >= 4.0.0, < 4.0.2
- vulnerable
- zbateson/mail-mime-parser >=4.0.0,<4.0.2|<3.0.6
- vulnerable
- ≥ 3.0.6
- patched
- ≥ 4.0.2
- patched
Reported fixes
Both vulnerabilities are fixed in versions 3.0.6 and 4.0.2. For the resource consumption issue, the fix adds configurable limits on multipart nesting depth and on header count/total header size (recording a parse error past the threshold instead of throwing), and changes sibling append handling to linear (O(n)) complexity. For the CRLF injection issue, the fix sanitizes attachment filenames before they are placed into header values. Users on end-of-life 1.x or 2.x versions will not receive patches and should upgrade to a currently maintained, fixed release.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email