Skip to content

MIME-Version header parsing leaks ValueError for oversized numeric components #158707

Description

@augusto-rehfeldt

Bug report

Bug description:

Documented behaviour: MIMEVersionHeader.value_parser documents the grammar as "mime-version = [CFWS] 1digit [CFWS] "." [CFWS] 1digit [CFWS]". BaseHeader's subclass contract states: "The parser should not, insofar as practical, raise any errors. Defects should be added to the list instead." Neither grammar repetition imposes a digit-count bound.

Expected: Construct the header without raising; record a defect if the version components cannot be represented under the active conversion limit.

Actual: Header construction raises ValueError when the major version contains 4301 digits and the integer-string conversion limit is 4300.

import re
import sys
import email.headerregistry as hr

limit = getattr(sys, "get_int_max_str_digits", lambda: 0)()
value = "1" * (limit + 1 if limit else 4301) + ".0"
expected = "constructed without exception" if re.fullmatch(r"[0-9]+\.[0-9]+", value) else None

if expected is None:
    print("REFUTATION REJECTED: input does not match the documented grammar")
else:
    try:
        hr.HeaderRegistry()("MIME-Version", value)
    except Exception as e:
        print(f"REFUTATION CONFIRMED: input={value!r}\nactual: {type(e).__name__}: {e}\nexpected: {expected}")
    else:
        print("REFUTATION REJECTED: constructed without exception")

Output on Python 3.14.6 (Windows-11-10.0.26220-SP0), standard library email.headerregistry:

111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111.0'
actual: ValueError: Exceeds the limit (4300 digits) for integer string conversion: value has 4301 digits; use sys.set_int_max_str_digits() to increase the limit
expected: constructed without exception

This report was found and written by an automated property-testing tool I run (bugforge). The reproducer above was executed and its output is pasted unedited; no person reviewed the report before it was filed. The search script is in https://github.com/augusto-rehfeldt/bugforge-results/tree/main/email.headerregistry-20261003-060502-c4

CPython versions tested on:

3.14

Operating systems tested on:

Windows

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions