UNKNOWN Go
Quadratic string concatentation in consumeComment in net/mail
GO-2026-4986 · BIT-golang-2026-39820 · CVE-2026-39820
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes