CVE-2026-100702
- EPSS 0.25%
- Veröffentlicht 26.09.2026 13:23:57
- Zuletzt bearbeitet 30.09.2026 16:32:17
Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array...
- EPSS 0.11%
- Veröffentlicht 26.09.2026 13:23:57
- Zuletzt bearbeitet 30.09.2026 16:32:17
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same no...
CVE-2026-100700
- EPSS 0.28%
- Veröffentlicht 26.09.2026 13:23:56
- Zuletzt bearbeitet 30.09.2026 16:32:17
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs t...
CVE-2026-100699
- EPSS 0.19%
- Veröffentlicht 26.09.2026 13:23:55
- Zuletzt bearbeitet 30.09.2026 16:32:17
Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-se...
CVE-2026-92598
- EPSS 0.26%
- Veröffentlicht 16.09.2026 21:47:02
- Zuletzt bearbeitet 22.09.2026 20:25:55
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with i...
CVE-2026-92597
- EPSS 0.26%
- Veröffentlicht 16.09.2026 21:47:01
- Zuletzt bearbeitet 22.09.2026 20:25:55
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of...
CVE-2026-92596
- EPSS 0.45%
- Veröffentlicht 16.09.2026 21:47:00
- Zuletzt bearbeitet 22.09.2026 20:25:55
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email w...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 21:47:00
- Zuletzt bearbeitet 22.09.2026 20:25:55
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the docum...
CVE-2026-90776
- EPSS 0.48%
- Veröffentlicht 13.09.2026 11:42:26
- Zuletzt bearbeitet 24.09.2026 20:47:31
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to...
CVE-2026-82854
- EPSS 1.13%
- Veröffentlicht 31.08.2026 08:46:28
- Zuletzt bearbeitet 10.09.2026 15:48:28
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatena...