Nodemailer
This hub aggregates every CVE we track for Nodemailer, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
27
CVEs tracked
1
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH6CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
1
1
0
4
0
7
9
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Nodemailer.
- CVE-2026-92598Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass6.5
- CVE-2026-92597Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment6.5
- CVE-2026-92595Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent5.9
- CVE-2026-92596Nodemailer before 9.1.0 Denial of Service via addressparser7.5
- CVE-2026-90776Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing7.5
- GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
- GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
- GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
- GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
- CVE-2026-82854Nodemailer before 8.0.3 SMTP Command Injection via envelope.size9.8
- CVE-2026-82853Nodemailer before 8.0.5 SMTP Command Injection via CRLF4.9
- CVE-2026-82661Nodemailer CRLF Injection via List-* Header Comments5.4
- CVE-2026-82662Nodemailer before 8.0.8 TLS Certificate Validation Bypass6.5
- CVE-2026-82660Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess5.4
- CVE-2026-82659nodemailer before 9.0.1 File Read and SSRF via raw option7.1
Product normalization is registry-driven with AI assist and human review. How it works