目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-100699— Nodemailer 10.0.9 前 信封收件人格式错误漏洞

一分钟漏洞结论

影响对象
nodemailer nodemailer
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Nodemailer 是一个用于 Node.js 的邮件发送库。在版本 >= 9.1.0 且 < 10.0.9 中,地址解析器(src/addressparser)在处理本地部分为引号字符串、且后跟 RFC 5322 注释的地址时存在处理不当的问题,导致尾随的、由注释分隔的域名原子被保留在规范化后的地址中。例如,输入 会被解析为地址值 ,其中包含由字面空格分隔的、由攻击者可控的额外域名文本。在构建邮件信封时(src/mime-node 中的 envelope.to),该解析后的值未经过严格的收件人验证便被直接使用,

CVSS 5.3 · Medium EPSS 0.19% · P8

可能的 ATT&CK 技术 1 AI

T1534 · Internal Spearphishing
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-100699 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment
来源: CVE Program / CVE List V5
Vulnerability Description
Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For example, the input "user"@example.com(x)evil.com is parsed to the address value 'user@example.com evil.com', which contains additional attacker-controlled domain text separated by a literal space. This parsed value is used without further strict recipient validation when the message envelope is built (envelope.to in src/mime-node), so a malformed/ambiguous recipient address can be accepted and placed in the SMTP envelope. Whether this results in delivery to an unintended recipient on real SMTP servers has not been confirmed. The issue is a variant of the RFC 5322 comment parsing problem addressed in GHSA-cc9r-2j5m-2m83, affecting the separate quoted-local-part code path. Version 10.0.9 contains a fix.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
nodemailer nodemailer 9.1.0 ~ 10.0.9 -

二、漏洞 CVE-2026-100699 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-100699 的情报信息

请登录查看更多情报信息。

CVE-2026-100699 厂商安全公告 (1)

CVE-2026-100699 其他参考 (1)

同批安全公告 · nodemailer · 2026-09-26 · 共 4 条

CVE-2026-100700 7.5 HIGH nodemailer 10.0.6 之前地址解析器拒绝服务漏洞
CVE-2026-100702 5.9 MEDIUM Nodemailer <10.0.2 递归收件人数组导致的栈溢出漏洞
CVE-2026-100701 5.9 MEDIUM Nodemailer 5.0.0-10.0.1 TLS服务器名混淆漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-100699

暂无评论


发表评论