nodemailer
16 known vulnerabilities in nodemailer, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100702 CVSS 8.2 high Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to…
- CVE-2026-100701 CVSS 6.0 medium Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also…
- CVE-2026-100700 CVSS 8.7 high nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits…
- CVE-2026-100699 CVSS 6.9 medium Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles…
- CVE-2026-92598 CVSS 8.3 high Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to…
- CVE-2026-92597 CVSS 8.3 high Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed…
- CVE-2026-92596 CVSS 8.7 high Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to…
- CVE-2026-92595 CVSS 6.0 medium Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox…
- CVE-2026-90776 CVSS 8.7 high Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing…
- CVE-2026-82854 CVSS 9.3 critical Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application…
- CVE-2026-82853 CVSS 6.9 medium Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands…
- CVE-2026-82662 CVSS 8.3 high Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers…
- CVE-2026-82661 CVSS 5.3 medium Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject…
- CVE-2026-82660 CVSS 5.3 medium Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport…
- CVE-2026-82659 CVSS 7.1 high nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated…
- CVE-2024-58379 CVSS 6.9 medium nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is…