Junglewise Threat Intelligence

CVE-2026-42504: Google Go CPU exhaustion in mime WordDecoder.DecodeHeader

CVE-2026-42504 · Severity: info · CVSS 0 · Published 2026-06-02

Vendors: Google.

Executive brief

A vulnerability in the Go programming language's standard library can allow an attacker to cause a denial-of-service condition. By sending a specially crafted email or web header, an attacker can force the application to consume excessive processor power, potentially slowing down or crashing the service. This affects any Go-based application that processes MIME headers, such as mail servers or web applications.

Technical details

A vulnerability exists in the 'mime' package's WordDecoder.DecodeHeader function due to quadratic complexity when handling invalid encoded-words. When the decoder encounters an invalid encoded-word, it consumes only the initial '=?' prefix and resumes parsing from that point. An attacker can exploit this by providing a header with many nested or repeated '=?' prefixes followed by a single terminal '?=', causing the decoder to repeatedly re-scan the input. This leads to excessive CPU consumption (Denial of Service). The issue is fixed in Go versions 1.25.11 and 1.26.4.

Affected products

  • Google Go before 1.25.11, 1.26.0 before 1.26.4

Timeline

  • 2026-05-05: disclosed: Issue opened on Go GitHub repository
  • 2026-06-02: advisory: CVE-2026-42504 published
  • 2026-06-02: patched: Fixed in Go 1.25.11 and 1.26.4

References