CVE-2026-55618
## Summary `eml_parser` performs certain validations on potential URL strings to discard bogus values. In versions prior to `3.0.2`, this validation was performed before unescaping any HTML entities that might occur in the string. This caused the library to wrongfully reject valid URLs that use HTML entities for the `:`, `/`, or `.` characters. These URLs would then not be included in the list of extracted URLs. Similarly, the host parts of such URLs would not be extracted. For example, neither the URL `https://phishing.example.com` nor its host (`phishing.example.com`) would appear in the parsing result. ## Impact `eml_parser` is used in email security gateways and SOC pipelines to extract URLs as IOCs. Those URLs are then checked against threat-intel feeds, URL reputation services, and sandboxes. A URL that is not extracted is never checked. ## Patches Since version 3.0.2 the library unescapes all HTML entities in every URL before deciding to accept or reject it. A test was added to prevent regressions.
Properties
- ghsa_id
- GHSA-fxgq-9m89-cxj9
- severity
- medium
- summary
- eml_parser has a URL extraction bypass via HTML entities in URLs
- cvss_score
- 6.5
- cve_id
- CVE-2026-55618
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-08-25T18:23:16Z
- source_url
- https://github.com/advisories/GHSA-fxgq-9m89-cxj9
- ghsa_updated
- 2026-08-25T18:23:17Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph