Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Excessive CPU consumption in ParseAddress in net/mail

GO-2025-4006 · BIT-golang-2025-61725 · CVE-2025-61725

Published · Modified

Description

The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.

Ready to move

Start Securing

Free, no credit card | First findings in minutes