THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mvxr-6m87-mv2q (medium) — Mail: Email address spoofing via malformed RFC 2047 encoded-words

[GHSA] GHSA-mvxr-6m87-mv2q (medium) — Mail: Email address spoofing via malformed RFC 2047 encoded-words

medgithub_advisoriesPublished 2026-09-02

GHSA-mvxr-6m87-mv2q Severity: medium CVE: CVE-2026-63435

Mail: Email address spoofing via malformed RFC 2047 encoded-words

## Summary

Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode decoded only the first RFC 2047 encoded-word in a string and used an overly greedy pattern to match the charset token. A crafted, malformed encoded-word embedded in an address display name or local

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mvxr-6m87-mv2q