PT-2026-20939 · Unknown · Mail-Parser+1

Proxforge

·

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2026-26312

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Stalwart Mail Server versions 0.13.0 through 0.15.4
Description A denial-of-service condition exists in Stalwart Mail Server when processing specially crafted emails. Accessing an email with malformed nested message/rfc822 MIME parts through IMAP or JMAP can lead to excessive CPU and memory usage, potentially causing an out-of-memory condition and server crash. The issue stems from cyclical references created by the mail-parser crate during parsing, which Stalwart then indefinitely processes.
Recommendations Versions prior to 0.15.5 are affected. Update to version 0.15.5 or later to resolve this issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-26312
GHSA-JM95-876Q-C9GW

Affected Products

Stalwart Mail Server
Mail-Parser