{"id":"CVE-2026-82520","summary":"parsedmarc \u003c 11.0.1 Zip Bomb DoS via Compressed Email Attachments","details":"parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically processes incoming DMARC report emails without user interaction, an unauthenticated remote attacker can send a crafted email with a highly compressed attachment to the monitored mailbox, causing the parsedmarc process to allocate memory proportional to the uncompressed size and exhaust available RAM.","aliases":["GHSA-43qf-f35w-2x4r"],"modified":"2026-09-06T03:30:29.065852518Z","published":"2026-09-03T20:39:00.723Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82520.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-409"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82520.json"},{"type":"ADVISORY","url":"https://github.com/domainaware/parsedmarc/security/advisories/GHSA-43qf-f35w-2x4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82520"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/parsedmarc-zip-bomb-dos-via-compressed-email-attachments"},{"type":"FIX","url":"https://github.com/domainaware/parsedmarc/releases/tag/11.0.1"},{"type":"PACKAGE","url":"https://github.com/domainaware/parsedmarc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/domainaware/parsedmarc","events":[{"introduced":"0"},{"fixed":"09c88ca2a36af198ebcc85413ce2fa92ff555093"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"11.0.1"}]}}],"versions":["11.0.0","10.5.0","10.4.3","10.4.2","10.4.1","10.4.0","10.3.0","10.2.4","10.2.2","10.2.1","10.2.0","10.1.1","10.1.0","10.0.4","10.0.3","10.0.0","9.11.2","9.11.1","9.11.0","9.10.3","9.10.2","9.10.1","9.10.0","9.9.0","9.8.0","9.7.1","9.7.0","9.6.0","9.5.5","9.5.4","9.5.3","9.5.2","9.5.1","9.5.0","9.4.0","9.3.1","9.3.0","9.2.1","9.2.0","9.1.2","9.1.1","9.0.10","9.0.7","9.0.6","9.0.3","9.0.2","8.19.1","8.19.0","8.18.7","8.18.6","8.18.5","8.18.4","8.18.3","8.18.2","8.18.1","8.17.0","8.16.1","8.16.0","5.17.0","5.16.0","8.15.4","8.15.2","8.15.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82520.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}