Updated: 2025-08-20 01:50:24.467494
Description:
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | HIGH | 7.5 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| EL 8 | python | 3.6 | 7.5 | HIGH | Ignored | 2025-05-24 05:23:30 | We've reasoned not to fix this CVE since project's upstream does not consider it as a bug or vulnera... | |
| EL 9 | python | 3.6 | 7.5 | HIGH | Ignored | 2025-05-24 05:23:29 | This CVE was disputed by the upstream developers because email.utils.parseaddr() acts as documented:... | |
| EL 9 | python | 2.7 | 7.5 | HIGH | Ignored | 2025-07-22 00:53:04 | This CVE was disputed by the upstream developers because email.utils.parseaddr() acts as documented:... | |
| Ubuntu 16.04 | python | 2.7 | 7.5 | HIGH | Ignored | 2025-09-05 20:05:28 | ||
| Ubuntu 16.04 | python | 3.6 | 7.5 | HIGH | Ignored | 2025-05-24 05:23:29 | ||
| Ubuntu 18.04 | python | 2.7 | 7.5 | HIGH | Ignored | 2025-09-05 20:05:27 | ||
| Ubuntu 18.04 | python | 3.6 | 7.5 | HIGH | Ignored | 2025-05-24 05:23:29 | ||
| Ubuntu 20.04 | python | 2.7 | 7.5 | HIGH | Ignored | 2025-09-05 20:05:27 | ||
| Ubuntu 20.04 | python | 3.6 | 7.5 | HIGH | Ignored | 2025-05-24 05:23:29 | ||
| Ubuntu 22.04 | python | 2.7 | 7.5 | HIGH | Ignored | 2025-09-05 20:05:26 |