CVE-2018-18898: Bestpractical Request Tracker

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

Affected products

  • Bestpractical Request Tracker: from 4.1.13, up to and including 4.4.0
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 10.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only

Published 2019-03-21. Last modified 2026-06-17.