CVE-2023-36632

    Dashboard / Vulnerabilities / CVE-2023-36632

    CVE-2023-36632

    Published: 25 Jun 2023Last Modified: 12 Aug 2026

    Summary:

    Details: The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v3.11.3
    v3.11.2
    v3.11.1
    v3.11.0rc2
    v3.11.0rc1
    v3.11.0b5
    v3.11.0b4
    v3.11.0b3
    v3.11.0b2
    v3.11.0b1
    v3.11.0a7
    v3.11.0a6
    v3.11.0a5
    v3.11.0a4
    v3.11.0a3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-36632 | CVE-DB