FlawAtlas
Search the atlas
CVE-2024-24784 High

Comments in display names are incorrectly handled in net/mail

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

Exploit probability 1.0%
Published March 5, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go stdlib
Bitnami golang
Chainguard cluster-autoscaler-1.27
Chainguard cluster-autoscaler-1.27-compat
Wolfi cluster-autoscaler-1.27
Wolfi cluster-autoscaler-1.27-compat
Chainguard cluster-autoscaler-1.28
Chainguard cluster-autoscaler-1.28-compat
Wolfi cluster-autoscaler-1.28
Wolfi cluster-autoscaler-1.28-compat
Chainguard newrelic-fluent-bit-output

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-24784

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

View original source
Open Source Vulnerabilities GO-2024-2609

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

View original source
Open Source Vulnerabilities BIT-golang-2024-24784

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

View original source

05 / REFERENCES

Further evidence