mediumCVSS 6.5Vulnerability

CVE-2026-55618

## Summary `eml_parser` performs certain validations on potential URL strings to discard bogus values. In versions prior to `3.0.2`, this validation was performed before unescaping any HTML entities that might occur in the string. This caused the library to wrongfully reject valid URLs that use HTML entities for the `:`, `/`, or `.` characters. These URLs would then not be included in the list of extracted URLs. Similarly, the host parts of such URLs would not be extracted. For example, neither the URL `https://phishing.example.com` nor its host (`phishing.example.com`) would appear in the parsing result. ## Impact `eml_parser` is used in email security gateways and SOC pipelines to extract URLs as IOCs. Those URLs are then checked against threat-intel feeds, URL reputation services, and sandboxes. A URL that is not extracted is never checked. ## Patches Since version 3.0.2 the library unescapes all HTML entities in every URL before deciding to accept or reject it. A test was added to prevent regressions.

Properties

ghsa_id
GHSA-fxgq-9m89-cxj9
severity
medium
summary
eml_parser has a URL extraction bypass via HTML entities in URLs
cvss_score
6.5
cve_id
CVE-2026-55618
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-08-25T18:23:16Z
source_url
https://github.com/advisories/GHSA-fxgq-9m89-cxj9
ghsa_updated
2026-08-25T18:23:17Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/eml_parser

AFFECTS (1)

[Software]pip/eml_parser

HAS_WEAKNESS (1)

[Weakness]Improper Encoding or Escaping of Output

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55618 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal