Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fxgq-9m89-cxj9 | eml_parser has a URL extraction bypass via HTML entities in URLs |
Tue, 25 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Govcert-lu
Govcert-lu eml Parser |
|
| Vendors & Products |
Govcert-lu
Govcert-lu eml Parser |
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash, or period characters. Valid encoded URLs and their host names are therefore rejected and omitted from the extracted URL and domain lists. Email security gateways and SOC pipelines that use those lists as indicators of compromise may fail to submit the hidden URLs to threat intelligence feeds, reputation services, or sandboxes, allowing malicious links to bypass inspection. This issue is fixed in version 3.0.2. | |
| Title | eml_parser: URL extraction bypass via HTML entities in URLs | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T18:21:56.178Z
Reserved: 2026-06-16T23:31:22.446Z
Link: CVE-2026-55618
No data.
Status : Received
Published: 2026-08-25T19:16:50.323
Modified: 2026-08-25T19:16:50.323
Link: CVE-2026-55618
No data.
OpenCVE Enrichment
Updated: 2026-08-25T20:30:17Z
Github GHSA