PT-2026-20939 · Unknown · Mail-Parser+1
Proxforge
·
Published
2026-02-19
·
Updated
2026-02-19
·
CVE-2026-26312
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Stalwart Mail Server versions 0.13.0 through 0.15.4
Description
A denial-of-service condition exists in Stalwart Mail Server when processing specially crafted emails. Accessing an email with malformed nested
message/rfc822 MIME parts through IMAP or JMAP can lead to excessive CPU and memory usage, potentially causing an out-of-memory condition and server crash. The issue stems from cyclical references created by the mail-parser crate during parsing, which Stalwart then indefinitely processes.Recommendations
Versions prior to 0.15.5 are affected.
Update to version 0.15.5 or later to resolve this issue.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stalwart Mail Server
Mail-Parser