CVE-2026-94440: Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart
Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.
Affected Software
Event History
Frequently Asked Questions
When can this memory-limit bypass occur?
It can occur while parsing a multipart form when the remaining memory limit at the start of a part is less than 400 bytes. In that condition, MIME header parsing can read an arbitrarily long line into memory despite the limit.
What is the practical impact for affected applications?
An affected application may allocate memory for an arbitrarily long MIME header line while processing multipart form data. This can defeat the application's expected memory limit for that parsing operation.
What input would an attacker need to provide?
The attacker would need multipart form data containing a part reached when fewer than 400 bytes remain under the parser's memory limit, with an arbitrarily long line in its MIME headers.