Skip to content

3.0.8

Choose a tag to compare

@zbateson zbateson released this 25 Sep 14:35
· 19 commits to 3.0 since this release

What's Changed

  • Add a configurable limit on the total number of parts in a message, recording a parse error when reached (override via DI config) -- thanks @iam-niranjan:
  • maxMessagePartCount (default 10000) — maximum parts per message, MIME and uu-encoded
  • Parse header values in O(n) rather than O(n²)
  • Add configurable limits to header parsing, each recording a parse error when reached (override via DI config): maxCommentDepth (default 32) — maximum nesting depth of parenthesised header comments
  • maxHeaderTokenCount (default 20000) — maximum tokens parsed from a single header value; the remainder is kept as one unparsed token

Security

This release fixes a reported vulnerability:

Reported by @iam-niranjan, who identified the unbounded part counts and proposed fixes that informed the patches; the header parsing issues were found during the resulting review. Upgrading is recommended.