PYSEC-2026-3833

    Dashboard / Vulnerabilities / PYSEC-2026-3833

    PYSEC-2026-3833

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: eml_parser has parser DoS via deeply nested parentheses in e-mail headers

    Details: ### Summary `eml_parser` uses the `email.utils.getaddresses()` function from the CPython standard library to parse e-mail headers that contain e-mail addresses (such as `To`, `Cc`, `Bcc`, `From`, `Reply-To`, `Sender`, ...). When the input header contains a deeply nested CFWS (comment / folding white space) construct, the recursive descent parser in the standard library exhausts the call stack. The resulting `RecursionError` is not caught by `eml_parser`, so the exception propagates and aborts parsing of the whole message. ### Impact SOC pipelines use `eml_parser` to process untrusted e-mails. An attacker can easily create an eml file that will trigger the `RecursionError` during parsing. The impact is mitigated by the fact that there are various other situations in which `eml_parser` will raise an exception when attempting to parse a malformed or pathological eml file. In particular, very deeply nested multipart e-mails also result in a `RecursionError` being raised by the library voluntarily. Therefore, systems relying on `eml_parser` already need to detect and handle errors emanating from the library in an appropriate way. ### Workarounds The issue can be avoided by wrapping the call to `eml_parser.decode_email` or `eml_parser.decode_email_bytes` in a `try/except` construct. ### Patches Since version 3.0.2, `eml_parser` will catch the error in the standard library parser and fall back to a simpler parser based on a regular expression.

    Affected packages

    Package

    Name: eml-parser

    Purl: pkg:pypi/eml-parser

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.0.2

    Affected versions

    0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3833 | CVE-DB