An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17846.json"