mime vulnerabilities
CVEs whose affected-version data names the mime package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42504High· 7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
▾ TwilightGo standard library · mimeEPSS 0.56%via CVEORG
CVE-2017-16138High· 7.5The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
▾ Twilightmime_project · mimeEPSS 2.2%via NVD