Skip to content

Mail with an outlook "bookwithme" link and long x-microsoft-antispam-message-info makes inbox inaccessible #11416

@rasos

Description

@rasos

Steps to reproduce

  1. Receive a mail with a long x-microsoft-antispam-message-info and a bookwithme link
  2. Inbox shows error (Inbox could not open)
  3. Put this mail into a quarantine folder (with Thunderbird)
  4. Inbox works again

The link was: https://outlook.office.com/bookwithme/user/68.....69@p.....m.com?anonymous&ep=signature

Expected behavior

Mailbox should remain accessible, even with bookwithme links.

Actual behavior

User could not open Inbox, after he got the mail with a bookwithme link.

Mail app version

3.7.24

Nextcloud version

29.0.10

Mailserver or service

own mail server postfix

Operating system

Debian

PHP engine version

PHP 8.1

Nextcloud memory caching

No response

Web server

Apache (supported)

Database

MariaDB

Additional info

Mail body, partially obfuscated and stripped (also contained base64 images):

From: M H <m.h......@p....m.com>
To: S B <sb@d.....eu>
Subject: Description
Thread-Topic: Description
Thread-Index: AQ.....XQ==
Date: Wed, 23 Jul 2025 15:48:50 +0000
Message-ID:
 <H....eurprd05.prod.outlook.com>
Accept-Language: es-ES, ca-ES, en-GB, en-US
Content-Language: es-ES
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed)
 header.d=none;dmarc=none action=none header.from=p.....com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: HE1P...:EE_|AS1P...38:EE_
x-ms-office365-filtering-correlation-id: 2f59e51c-562b-453a-dc0f-08ddca006b50
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam:
 BCL:0;ARA:13230040|1800799024|376014|366016|69100299015|4022899009|13003099007|4053099003|8096899003|38070700018;
x-microsoft-antispam-message-info:
 =?ks_c_5601-1987?B?QmN0TkJnekkwTlhYSHF6ZG1iZEpEVWdrbElETmd5VC8waWxBb2Ja?=
 =?ks_c_5601-1987?B?ZTRRT0ltcHMyTmJDdEczVTNJRnlVUlJUejF3OW15aWF1SDRwTU1C?=
 =?ks_c_5601-1987?B?YXZaaWVLWU9Ea2JzbjRkYnRxbzV0UEo1bWF2K2lzNThCL0phN0hK?=
 =?ks_c_5601-1987?B?V2UxSTA4N1FWUUxPVVpmQWRTQ09YazFLR1lTYzRKbGExdU5iTW03?=
 =?ks_c_5601-1987?B?TmlkQ2swdXdsWWpoWitxeHlORmN4em9DLzVhVWVHV2dvZTN5Zyt1?=
 =?ks_c_5601-1987?B?akRub2RzQS9oWXZvdFhqMFFRY2hDd25hdTZVd1U4L0xtdG5ac3d3?=
 =?ks_c_5601-1987?B?SjBVWndsc01NQ1RLaS91a0NOUUlqRDFKZllHOWlqblROQWJCSngz?=
 =?ks_c_5601-1987?B?WVExb3Z2Y3llUE1TdUltcW94Yk1uYlEzbE5qNlhxRGVSbHNyZElM?=
 =?ks_c_5601-1987?B?QUhpTy9sVG56OVV6SkNHNjRURVhkSzdqQU1xTkl0Y2JqVThaWm00?=
 =?ks_c_5601-1987?B?cFZFWmhjckpzMDFOOEhYOHZIaTFTZmVXVE1neG5iL2J4NENNN0Q1?=
 =?ks_c_5601-1987?B?dlAxbHRZVkx4SWRhbjl6a3RKYmNrZnhuZjhmRlNWTlR6NVQvaXk0?=
 =?ks_c_5601-1987?B?SlhzUmJwRnF1R1hpSDNzem9ST0RUUFV5NGJLcVBFdTBsL0JJR1N3?=
 =?ks_c_5601-1987?B?Z1FkeWdsRG9DbFJUNjhMSDdZMnZWUEhoTHBQQW9OY0ZxYnU5RnpY?=
 =?ks_c_5601-1987?B?NFZ0TGtmTVhXYWN5SzhkMU56eXQ2ZHFjRFFkSUtKdndWNFgvckMr?=
 =?ks_c_5601-1987?B?OUpDNllZQUxoUFN6eXIya1NwdEVLNzVmVlRoOFYvWDJ6UTdkR0F6?=
 =?ks_c_5601-1987?B?YjFscTdCckI3Z3FaRnoxbTdKenkxTytaaTRFV0xsOXlxN2p5U3po?=
 =?ks_c_5601-1987?B?cFM0Y09wZlJ1b2lnQUVmU1I1NnFCVFJUd2ZkWjB4SGVIcnJFRjlh?=
 =?ks_c_5601-1987?B?Zk1YSmNubE9lTzNTbU1KRUJpWk9KUFZPTkNvY200Yk5DYVFkNlEw?=
 =?ks_c_5601-1987?B?S3FrdE5SNE56Y1d3YURpM05VdU9QRDFDbk13V1J1WmZocDNjOVcz?=
 =?ks_c_5601-1987?B?ZGxKd0s2QndkMkVQMEZkZHF6YTdnQ1RXUUxqam1GLzIrRklSTzNF?=
 =?ks_c_5601-1987?B?N1N5MStRdnVHVDhiUnpzQklXSVE4Q0hBV2trd2oxNEpyMnl2clg5?=
 =?ks_c_5601-1987?B?WUtGbmJoaHVrR1BxWkxtUFAyWVd5ZXZqWFRDWDM3VTVSU2R6bU1t?=
 =?ks_c_5601-1987?B?VkIyOFl2ZTZLelBUVzhhSTRWK2Z2MytKWU1lS3l2MXhLRHVOdHJz?=
 =?ks_c_5601-1987?B?Ym9OTWVyclZDYzVVS2poTlMxTEd5NE1lVnlRU3FNeVZiSXNtUWVZ?=
 =?ks_c_5601-1987?B?MTJLdGtFY0pyUksrL2EwVkVzUktpcHJWd0hXblFBVFNieXZUaVha?=
 =?ks_c_5601-1987?B?aUVPcnF2OHhiNHcxZGNOcGgxS0xvUEVNdVFnWmNtdm95STZ0Q0xj?=
 =?ks_c_5601-1987?B?Lyt1RXhqM1AvRnk1Y1c5ME5wSXE1NTE4QXN1RzQvTUhIK1JvQ3FR?=
 =?ks_c_5601-1987?B?RkFpVUhwV1ZmVnRtNFhvbXViOGNzSlpiblFHUnpFbVJ6VE9xODlY?=
 =?ks_c_5601-1987?B?ZEY1dGhsOEg3aFZVUUF2cXBGVm80dEowZG5XZE41SU1Mb296dDV5?=
 =?ks_c_5601-1987?B?Z29wbUMyd2QvLzU3TWFBcW12cXNlWW9PRHkwb0pla09YcHFMUDFT?=
 =?ks_c_5601-1987?B?R050cFFvNmtZVVV3Zk9jVEx5UlZZNGZIN3dxeDdCRFp4aCtDWkJx?=
 =?ks_c_5601-1987?B?d014UHJzNklrSGhUM2pXSmRnUEZ3RVlqb1JjcDY0dUd6Yi8vYklo?=
 =?ks_c_5601-1987?B?clQ4NWVtWGFpWXhOQnBoUkg4U2ROQU1ISnh3ZTRoNFBzc0w4TE4v?=
 =?ks_c_5601-1987?B?N0J4S1FPSFMxTkFkM2swYTg3ak41Y3dtQm9BY1RXZnJyeHNhb3I2?=
 =?ks_c_5601-1987?B?R2d6MXluTVB3QkN3bWljdWtvSm9TaThRT00zR3N3WGVHN3BHa01z?=
 =?ks_c_5601-1987?B?MEs2VC8rMmgvbDQxZ29hYUcwN295eGlpYmgvRCtYc1VDdE5sU3ZW?=
 =?ks_c_5601-1987?B?QzVMalpQZUFncVRqM2FhdUxyeG1oY01mN210S21ycU8ybDE1Qmxz?=
 =?ks_c_5601-1987?Q?MTLc5LCE=3D?=
x-forefront-antispam-report:
 CIP:255.255.255.255;CTRY:;LANG:ko;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:HE1PR....07.eurprd05.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(69100299015)(4022899009)(13003099007)(4053099003)(8096899003)(38070700018);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0:
 =?ks_c_5601-1987?B?ck1iQTlBMjJQbXdqK09lbXRUZUZoTjV4MmFyeU9VYzhtcUZIRHNx?=
 =?ks_c_5601-1987?B?U1JVaXpuYkxUbkdrQ3Z6c3NlNVhkUU5WL0N4NU40YUJTMmtESnBW?=
 =?ks_c_5601-1987?B?VEJhVTFVelNiVEkwa2h5cHVsR3RWUmJtQlJ3NzVUd2VTVjhNcGky?=
 =?ks_c_5601-1987?B?cE0rZ0VVMXhxWTVHekFxdjg3YklBYi84VktTZDhURG82Wkw5OFdo?=
 =?ks_c_5601-1987?B?Y1laMXlBWU5xd2pzNC9mbmNIZHhrR1UxcW9zVXNkMlNtd2hyYjlZ?=
 =?ks_c_5601-1987?B?NVRTMGFuSyt2T0s3RS9PL2czR01QWk5LUnVkRVVoSC91RU4ycGZa?=
 =?ks_c_5601-1987?B?ZmliemhLZTY1ZXJCQWtwdm10elhpYUlLcG0ySStRN1kvR3pWTHhS?=
 =?ks_c_5601-1987?B?ekVXd3hPZWM0LzkxOTNJNldLOWtINno0d0RSa2hpaDNvZ0Q4em1p?=
 =?ks_c_5601-1987?B?clloZFpzRk9xaGtiS2RneWhldWZ4dFJOWkk0MGErbHk5NzlBSWNJ?=
 =?ks_c_5601-1987?B?WWF3Sks3NTR0SnkrN2lLRHgrV2VxcU5FVXZ3eWM2RG9OMWU2bWhK?=
 =?ks_c_5601-1987?B?U08raDNVSU9KRDd3SEtSQ2pVZEsvWE5sakxTYnA2NVhNbWw4bXF1?=
 =?ks_c_5601-1987?B?eTE1RGFBcmJQVFh1d2pveVRqb0E0dlJrcW4yenJ2L2pxTkI5VzR2?=
 =?ks_c_5601-1987?B?aGxZbU5LcVp6ZGI0RkYvSWhIZ2hQc0hXNkNBTys5bUVEaXZ2Z0hv?=
 =?ks_c_5601-1987?B?eitsQ0JZK0dzOTdFdXRRY3VJdDFPR3A5RXhlV2czSXdKV3ZjZStl?=
 =?ks_c_5601-1987?B?dWR1azl1S2h4YXk4bFVCUFZ1dlRCSDdhTUxBUjJDRUd0WXRRTVM0?=
 =?ks_c_5601-1987?B?cVpiTkZTcWxIemVKTEQ2Y21qbUl6QnV2bzl6L2l5V1FmNWhYdTl6?=
 =?ks_c_5601-1987?B?dVg0QVpsaXRXYUFZeEFySmJjVFJWVXAxT1p3SnRvcXJhdW1ERTRj?=
 =?ks_c_5601-1987?B?aUdaTVpzd1BKUDdYVk5IeWg4L0lkV1ZveTdDV3ErMkZMbExBV1BS?=
 =?ks_c_5601-1987?B?VmpLVTFrNFJOVW02YUNRMzZQWUg3S0h6bWk2aWhDazZiMFJYNWho?=
 =?ks_c_5601-1987?B?ZmpsYnBycVhRcXVzQkZqUy81Y3Y5eTdzanJBQ1NxOWtDcGI1dTFC?=
 =?ks_c_5601-1987?B?MUszdUlkVFlkMXRleWY5L05FVTJrc0trdjNMbWhkNjRyRGNyVVU0?=
 =?ks_c_5601-1987?B?UFhhVXRzY2xtK2Mrc1c1bkUxWHN4dnlma1psTGxhSlhrTUljTTVZ?=
 =?ks_c_5601-1987?B?OUUzZzNQYWtaOWRTdDlhc1I2anlVUTFpQm9PVHJjZTJvMUIyMTRu?=
 =?ks_c_5601-1987?B?SGdSMDB6cFZjYXRlUGIva3VrUUxjcmgyY0NVNWI1SVNrbmZiYlNY?=
 =?ks_c_5601-1987?B?Q0xsMmxSaFhYMUs4Yi9Jd1Q2Q1VEY3VackRmRjBPVEt5Q0ZTb3Ru?=
 =?ks_c_5601-1987?B?ZVhReFlDL0lLYnlZZjBadFB6bkx4WTFwOVpNd0dmamxCU0tBMWVK?=
 =?ks_c_5601-1987?B?NlBTVTZDU1JuRUJtdGY4eU41bXZRQjdONHpuRWMzYUJsK0xIamU1?=
 =?ks_c_5601-1987?B?Z3ppcmZBUThYYjN6L2xJN3NieXpmYmF6d0NPSkRYZHIyZUdRMVFG?=
 =?ks_c_5601-1987?B?UUg2Ulh2TTNNNm9SdXY1U0JGT2UxY2ZVbEdyT1hyeWhUNFUvb1Rq?=
 =?ks_c_5601-1987?B?ZDFpSnZFazhmUnE5TWxaeFNOVHMxbkZEZ3NpQW41dmxLRm5zVUk4?=
 =?ks_c_5601-1987?B?Wno2UnRTeCt6VWkwVGhhbFNGQldIU2plbWxjdlRkUk94ZWtjaGZC?=
 =?ks_c_5601-1987?B?UzBpd2ppWHc1Zm1sbVlyMVQ3aFVRbjJlaGtPQ0xVUmxBdzNuQVRO?=
 =?ks_c_5601-1987?B?T29za2dBeTRpRGJSaFptRHhKUXI3S2RBTlYzUVlidmZSaytFSlNY?=
 =?ks_c_5601-1987?B?ME9KNUZBVEREckZVazRzUFo0UE8zTzJnMC8wRUI2NEdTNTJtSU0v?=
 =?ks_c_5601-1987?B?Q0d2czJCRXFWRTFMQUpReThVYkpnblQ1WCs1R2NvTlNteGtIUFhp?=
 =?ks_c_5601-1987?B?VldiUUZQRXZWdXBlUUFzdmNNb3BZRGhzOWlXQjJKMDcweWtocmxF?=
 =?ks_c_5601-1987?B?aWlUK1JpLzB2bzl2REFHUW5IN3hOTElMMVZzZFgxR05UbGVlYkxD?=
 =?ks_c_5601-1987?B?NjhZaS91Yy8zQzQ3L3VsNmdzcDQ4SG1MZ2RBQzJybzU3UkZ0RWFp?=
 =?ks_c_5601-1987?B?MFBaWXhOQ1NENjZUWGZyVXNwcTN2TVlDcjdEcUFsMFRFR0tUMnhG?=
 =?ks_c_5601-1987?B?WTdYTmdXUG9Wc2w0RnJScjNSKzh1UHFicWpncU5rQ0lzRUsvVFBp?=
 =?ks_c_5601-1987?Q?cRjU/t+56/p8sQB2bNMcicvfKK+Ws5Vs03GW4fax?=
Content-Type: multipart/related;
	boundary="_004_HE1.....eurp_";
	type="multipart/alternative"
MIME-Version: 1.0
X-OriginatorOrg: p....com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: H....307.eurprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2...
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Jul 2025 15:48:50.3126
 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5...
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Lx/....==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS1PR05MB8738

--_004_HE1......eurp_
Content-Type: multipart/alternative;
	boundary="_000_HE1.....eurp_"

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dks_c_5601=
-1987">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web (West E=
uropean)&quot;, &quot;Helvetica Neue&quot;, sans-serif; font-size: 12pt; co=
lor: rgb(0, 0, 0);" class=3D"elementToProof">
Hi Slawek!</div>
<div style=3D"font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web (West E=
uropean)&quot;, &quot;Helvetica Neue&quot;, sans-serif; font-size: 12pt; co=
lor: rgb(0, 0, 0);" class=3D"elementToProof">
Let's give this a try. See my analysis here (as I see it - don=A2=AEt take =
it as written in stone) and if you like it.</div>
<div style=3D"font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web (West E=
uropean)&quot;, &quot;Helvetica Neue&quot;, sans-serif; font-size: 12pt; co=
lor: rgb(0, 0, 0);" class=3D"elementToProof">
<b><br>
</b></div>
<div style=3D"font-family: &quot;Segoe UI&quot;, &quot;Segoe UI Web (West E=
uropean)&quot;, &quot;Helvetica Neue&quot;, sans-serif; font-size: 12pt; co=
lor: rgb(0, 0, 0);" class=3D"elementToProof">

...

<table id=3D"pbpsiglinktable">
<tbody>
<tr>
<td>
<div class=3D"elementToProof"><a class=3D"OWAAutoLink" id=3D"OWA77e2cefb-4b=
6e-7f7f-514b-daca9265a802" href=3D"https://outlook.office.com/bookwithme/user/68.....69@p.....m.com?anonymous&ep=signature"><img data-outlook-trace=3D"F:1|T:1" src=3D"cid:b1b46057-7142-4b93-9fc0=
-1044f52528c5"></a></div>
</td>
<td></td>
<td>
<div style=3D"color: rgb(0, 120, 212);" class=3D"elementToProof"><a style=
=3D"color: rgb(0, 120, 212); text-decoration: none;" class=3D"OWAAutoLink" =
id=3D"OWA7c87dee4-528d-a706-e8fb-7fff42cae5ff" href=3D"https://outlook.office.com/bookwithme/user/68.....69@p.....m.com?anonymous&ep=signature">Reservar
 un momento para reunirse conmigo</a></div>
</td>
<td></td>
</tr>
</tbody>
</table>
</div>
</body>
</html>

--_000_HE1.....eurp_--

--_004_HE1.....eurp_
Content-Type: image/png; name="Outlook-01lz5eva.png"
Content-Description: Outlook-01lz5eva.png
Content-Disposition: inline; filename="Outlook-01lz5eva.png"; size=528;
	creation-date="Wed, 23 Jul 2025 15:48:50 GMT";
	modification-date="Wed, 23 Jul 2025 15:48:50 GMT"
Content-ID: <b1b46057-7142-4b93-9fc0-1044f52528c5>
Content-Transfer-Encoding: base64

iV.................. 

--_004_HE1PR05MB3307D4F9CBA278111ECCA2BFF65FAHE1PR05MB3307eurp_--

Metadata

Metadata

Type

No fields configured for Bug.

Projects

Status

🏗️ In progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions