eml-parser vulnerabilities
CVEs whose affected-version data names the eml-parser package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-55618Medium· 6.5eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
▾ Sunliteml-parser · eml-parserEPSS 0.30%via OSV
CVE-2026-55619Medium· 5.3eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
▾ Sunliteml-parser · eml-parserEPSS 0.30%via OSV
CVE-2026-55620High· 7.5eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
▾ Twilighteml-parser · eml-parserEPSS 0.37%via OSV
CVE-2026-44844Mediumeml_parser has recursion DoS via nested message/rfc822 attachments
eml_parser has recursion DoS via nested message/rfc822 attachments
▾ Sunliteml-parser · eml-parserEPSS 0.40%via OSV
CVE-2026-29780Medium· 5.5PoCeml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
▾ Twilighteml-parser · eml-parserEPSS 0.24%via OSV