CVE-2014-4720: Email::address Module Project Email::address

Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.

Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase," a different vulnerability than CVE-2014-0477.

Affected products

  • Email::address Module Project Email::address: up to and including 1.903; version 1.1 only; version 1.2 only; version 1.3 only; version 1.5 only; version 1.6 only; …

Published 2014-07-06. Last modified 2026-06-17.