High severity7.5NVD Advisory· Published Sep 3, 2026
CVE-2026-82520
CVE-2026-82520
Description
parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically processes incoming DMARC report emails without user interaction, an unauthenticated remote attacker can send a crafted email with a highly compressed attachment to the monitored mailbox, causing the parsedmarc process to allocate memory proportional to the uncompressed size and exhaust available RAM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <11.0.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.