CVE-2026-94440 PUBLISHED

Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart

Assigner: Go
Reserved: 21.09.2026 Published: 08.10.2026 Updated: 08.10.2026

Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.

Product Status

Vendor Go standard library
Product net/textproto
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)
Vendor Go standard library
Product mime/multipart
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

Credits

  • Jakub Ciolek (https://ciolek.dev)

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling