The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade eml-parser to version 3.0.2 or higher.
eml-parser is a Python EML parser library
Affected versions of this package are vulnerable to Excessively Deep Nesting in the parsing process of e-mail headers containing deeply nested parentheses. An attacker can cause the application to exhaust the call stack and terminate unexpectedly by submitting specially crafted e-mail headers with deeply nested CFWS constructs.
This vulnerability can be mitigated by wrapping calls to decode_email or decode_email_bytes in a try/except construct to handle RecursionError exceptions.