Skip to content

3.0.9

Choose a tag to compare

@zbateson zbateson released this 28 Sep 20:34

What's Changed

  • Strip control characters from the MIME type, charset, transfer encoding, micalg and protocol arguments of the message-building API, as is already done for attachment filenames -- thanks @manus-pi, @AlpetGexha and @kemrec
  • Add configurable limits on the total number of headers, header bytes and header tokens parsed in a message, each recording a parse error when reached (override via DI config):
    • maxMessageHeaderCount (default 50000) — maximum headers read per message across all parts
    • maxMessageHeaderSizeBytes (default 8388608) — maximum header bytes read per message across all parts
    • maxMessageHeaderTokenCount (default 250000) — maximum header tokens parsed per message across all parts; headers parsed after it is reached are kept as one unparsed token each
  • Read past the rest of a part's headers when a header limit is reached, rather than treating them as the part's content
  • Skip building the error logging context when no logger is configured
  • Lower the default maxMessagePartCount from 10000 to 1000
  • Parse quoted header values in O(n) rather than O(n²) -- thanks @manus-pi
  • Parse address groups and RFC 2231 split parameters in O(n) rather than O(n²)
  • Match multipart boundary lines in constant time regardless of nesting depth
  • Parse each part's Content-Type header once rather than twice
  • Keep only the mime-encoded header parts that recorded decoding errors, rather than every part
  • Strip control characters from uuencoded part filenames and from the remaining message-building helper arguments

Security

This release fixes two reported vulnerabilities:

Reported by @manus-pi, @AlpetGexha and @kemrec; the unbounded per-message header memory was found during the resulting review. Upgrading is recommended.