{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/parsedmarc--11.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parsedmarc:parsedmarc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82520"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["parsedmarc (\u003c 11.0.1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","email-security"],"_cs_type":"advisory","_cs_vendors":["parsedmarc"],"content_html":"\u003cp\u003eThe parsedmarc library, a utility used for parsing DMARC reports, contains a critical vulnerability (CVE-2026-82520) in versions prior to 11.0.1. The vulnerability stems from the library performing a single, unbounded read when decompressing gzip and ZIP email attachments. Because parsedmarc is designed to automatically ingest and process emails from monitored mailboxes without user interaction, an unauthenticated remote attacker can exploit this behavior by sending a specially crafted, highly compressed attachment.\u003c/p\u003e\n\u003cp\u003eWhen parsedmarc attempts to decompress the malicious payload, it allocates memory proportional to the potential uncompressed size of the data. By providing a 'zip bomb' or similar high-compression ratio file, an attacker forces the application to consume excessive system memory, resulting in process crashes or total exhaustion of host RAM. This vulnerability is particularly dangerous due to the automated nature of the software, which facilitates unauthenticated remote exploitation without requiring any victim action beyond the delivery of the email to the monitored inbox.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial-of-service condition for the affected parsedmarc instance. Organizations relying on this tool for DMARC report processing will experience a loss of visibility into email authentication compliance and potential system instability for the host running the software. If the process is running on shared infrastructure, the memory exhaustion could impact other services co-located on the same host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of parsedmarc to version 11.0.1 or later to implement size limits on decompression.\u003c/li\u003e\n\u003cli\u003eImplement strict incoming email attachment size and content filtering at the Mail Transfer Agent (MTA) level to prevent highly compressed files from reaching the parsedmarc ingest mailbox.\u003c/li\u003e\n\u003cli\u003eMonitor system memory usage for the process handling parsedmarc execution to identify potential crash loops or anomalous spikes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T21:23:03Z","date_published":"2026-09-03T21:23:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-parsedmarc-dos/","summary":"The parsedmarc library before version 11.0.1 is vulnerable to remote denial-of-service exploitation via crafted email attachments that trigger memory exhaustion through unbounded decompression.","title":"Denial of Service in parsedmarc via Unbounded Attachment Decompression","url":"https://feed.craftedsignal.io/briefs/2026-09-parsedmarc-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Parsedmarc (\u003c 11.0.1)","version":"https://jsonfeed.org/version/1.1"}