HIGH 8.7 NVD
CVE-2026-92596
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of servic
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
References
- https://github.com/nodemailer/nodemailer/commit/34da642
- https://github.com/nodemailer/nodemailer/commit/7cc38af
- https://github.com/nodemailer/nodemailer/commit/83b8c48
- https://github.com/nodemailer/nodemailer/commit/9116da9
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.