← Back to CVE List
CVE-2026-92596NVD
Vulnerability Summary
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
CVSS v4.0 Base Metrics — Score 8.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- nodemailer nodemailer < 9.1.0
- nodemailer nodemailer 9.1.0
External References
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
- https://github.com/nodemailer/nodemailer/commit/9116da9
- https://github.com/nodemailer/nodemailer/commit/7cc38af
- https://github.com/nodemailer/nodemailer/commit/34da642
- https://github.com/nodemailer/nodemailer/commit/83b8c48
- https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-denial-of-service-via-addressparser