CVE-2018-12558: Email::address Module Project Email::address
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
Affected products
- Email::address Module Project Email::address: up to and including 1.909
Published 2018-06-20. Last modified 2026-06-17.