Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Comments in display names are incorrectly handled in net/mail

GO-2024-2609 · BIT-golang-2024-24784 · CVE-2024-24784

Published · Modified

Description

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

Ready to move

Start Securing

Free, no credit card | First findings in minutes