DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-61816: CVE-2026-61816: Uncontrolled Resource Consumption and Algorithmic Complexity in zbateson/mail-mime-parser

CVE-2026-61816: Uncontrolled Resource Consumption and Algorithmic Complexity in zbateson/mail-mime-parser

Vulnerability ID: CVE-2026-61816
CVSS Score: 7.5
Published: 2026-09-24

The PHP email processing library zbateson/mail-mime-parser is vulnerable to multiple algorithmic complexity exploits. By submitting small, highly structured email payloads, remote, unauthenticated attackers can trigger high CPU utilization or out-of-memory states, causing an application-wide denial of service.

TL;DR

A denial of service vulnerability in zbateson/mail-mime-parser allows unauthenticated remote attackers to trigger severe CPU exhaustion or out-of-memory crashes by submitting malformed emails under 2 MB containing deeply nested boundaries, large header lists, or dense sibling attachments.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.5 (High)
  • Impact: Denial of Service (DoS)
  • Exploit Status: Proof of Concept (PoC)
  • KEV Status: Not Listed

Affected Systems

  • zbateson/mail-mime-parser (PHP Package)
  • mail-mime-parser: >= 2.0.0, < 3.0.6 (Fixed in: 3.0.6)
  • mail-mime-parser: >= 4.0.0, < 4.0.2 (Fixed in: 4.0.2)

Code Analysis

Commit: 1691e69

Add configurations and validation loops to limit nesting depth and total header processing sizes.

Commit: fa44823

Optimize sibling MIME appending methods within PartChildrenContainer to run in linear time.

Mitigation Strategies

  • Update zbateson/mail-mime-parser to versions 3.0.6, 4.0.2, or newer.
  • Impose global constraints on memory_limit and max_execution_time within the PHP runtime configuration.
  • Deploy proxy-level or mail-transfer-agent (MTA) validation rules to drop exceptionally deep MIME hierarchies.

Remediation Steps:

  1. Run 'composer update zbateson/mail-mime-parser' to download version 3.0.6 or 4.0.2.
  2. Review custom DI container setups to ensure they inherit the default values for 'maxMimePartDepth', 'maxHeaderCount', and 'maxHeaderSizeBytes'.
  3. Set 'memory_limit' to a conservative threshold (e.g. 128M) in php.ini to contain potential OOM outcomes.

References


Read the full report for CVE-2026-61816 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)