CVE-2026-100702

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.

  • Published Sep 26, 2026
  • CVSS 8.2 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-100702 at the National Vulnerability Database