NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #489 most downloaded on Packagist
MIME email message parser
Last release 9 days ago
28 Sep 2026
Release timing varies
gaps range from 8 days to 1.2 years
Some releases are documented
notes for 16 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
79 releases · first in 2015
This release fixes two reported vulnerabilities:
maxMessageHeaderCount (default 50000) — maximum headers read per message across all partsmaxMessageHeaderSizeBytes (default 8388608) — maximum header bytes read per message across all partsmaxMessageHeaderTokenCount (default 250000) — maximum header tokens parsed per message across all parts; headers parsed after it is reached are kept as one unparsed token eachmaxMessagePartCount from 10000 to 1000This release fixes two reported vulnerabilities:
Reported by @manus-pi, @AlpetGexha and @kemrec; the unbounded per-message header memory was found during the resulting review. Upgrading is recommended.
One column per quarter.
Fixes #269 -- $streamPartEndPos in ZBateson\MailMimeParser\Parser\PartBuilder can be null when there is no body part in the mime message
Fixes #269 -- $streamPartEndPos in ZBateson\MailMimeParser\Parser\PartBuilder can be null when there is no body part in the mime message
Full Changelog: 4.0.4...4.0.5
This release fixes a reported vulnerability:
maxMessagePartCount (default 10000) — maximum parts per message, MIME and uu-encodedmaxCommentDepth (default 32) — maximum nesting depth of parenthesised header commentsmaxHeaderTokenCount (default 20000) — maximum tokens parsed from a single header value; the remainder is kept as one unparsed tokenThis release fixes a reported vulnerability:
Reported by @iam-niranjan, who identified the unbounded part counts and proposed fixes that informed the patches; the header parsing issues were found during the resulting review. Upgrading is recommended.
Allow Guzzle PSR-7 v3 by @simPod in #268
This release fixes two privately reported vulnerabilities:
maxMimePartDepth (default 256) — maximum multipart nesting depthmaxHeaderCount (default 1000) — maximum headers per partmaxHeaderSizeBytes (default 1048576) — maximum total header bytes per partrandom_bytes() -- thanks @iliaalThis release fixes two privately reported vulnerabilities:
Found and reported privately by @iliaal, who also proposed fixes that informed the patches. Upgrading is recommended.
Full Changelog : 4.0.0...4.0.1
Full Changelog: 4.0.0...4.0.1
Full Changelog : 3.0.5...4.0.0
Full Changelog: 3.0.5...4.0.0
This release fixes two reported vulnerabilities:
maxMessageHeaderCount (default 50000) — maximum headers read per message across all partsmaxMessageHeaderSizeBytes (default 8388608) — maximum header bytes read per message across all partsmaxMessageHeaderTokenCount (default 250000) — maximum header tokens parsed per message across all parts; headers parsed after it is reached are kept as one unparsed token eachmaxMessagePartCount from 10000 to 1000This release fixes two reported vulnerabilities:
Reported by @manus-pi, @AlpetGexha and @kemrec; the unbounded per-message header memory was found during the resulting review. Upgrading is recommended.
This release fixes a reported vulnerability:
This release fixes a reported vulnerability:
Reported by @iam-niranjan, who identified the unbounded part counts and proposed fixes that informed the patches; the header parsing issues were found during the resulting review. Upgrading is recommended.
This release fixes a reported vulnerability:
maxMessagePartCount (default 10000) — maximum parts per message, MIME and uu-encodedmaxCommentDepth (default 32) — maximum nesting depth of parenthesised header commentsmaxHeaderTokenCount (default 20000) — maximum tokens parsed from a single header value; the remainder is kept as one unparsed tokenThis release fixes a reported vulnerability:
Reported by @iam-niranjan, who identified the unbounded part counts and proposed fixes that informed the patches; the header parsing issues were found during the resulting review. Upgrading is recommended.
Claude-Session: https://claude.ai/code/session_01WnrkyxJU1CCZ6m8AVvdyCh
This release fixes two privately reported vulnerabilities:
maxMimePartDepth (default 256) — maximum multipart nesting depthmaxHeaderCount (default 1000) — maximum headers per partmaxHeaderSizeBytes (default 1048576) — maximum total header bytes per partrandom_bytes() -- thanks @iliaal.This release fixes two privately reported vulnerabilities:
Found and reported privately by @iliaal, who also proposed fixes that informed the patches. Upgrading is recommended.
Php 8.5 support by @phpfui in #260
Fix getAttachmentPart typo in IMessage.php docs by @seanmckenzie428 in #245
Full Changelog: 3.0.3...3.0.4
Fix to allow empty address groups #241
Full Changelog: 3.0.2...3.0.3
Replace global DI library functions with corresponding objects for PRS-4 compliance by @phpfui in #238
Full Changelog: 3.0.1...3.0.2
Fixes version constraints for php-di, guzzlehttp/psr7 and phpunit.
Fixes version constraints for php-di, guzzlehttp/psr7 and phpunit.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →