Nodemailer 是一个用于 Node.js 的邮件发送库。在版本 >= 9.1.0 且 < 10.0.9 中,地址解析器(src/addressparser)在处理本地部分为引号字符串、且后跟 RFC 5322 注释的地址时存在处理不当的问题,导致尾随的、由注释分隔的域名原子被保留在规范化后的地址中。例如,输入 会被解析为地址值 ,其中包含由字面空格分隔的、由攻击者可控的额外域名文本。在构建邮件信封时(src/mime-node 中的 envelope.to),该解析后的值未经过严格的收件人验证便被直接使用,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 9.1.0 ~ 10.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100700 | 7.5 HIGH | nodemailer before 10.0.6 Denial of Service via addressparser |
| CVE-2026-100702 | 5.9 MEDIUM | Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays |
| CVE-2026-100701 | 5.9 MEDIUM | Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion |
No comments yet