Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100699— Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment

Quick assessment

Affected
nodemailer nodemailer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nodemailer 是一个用于 Node.js 的邮件发送库。在版本 >= 9.1.0 且 < 10.0.9 中,地址解析器(src/addressparser)在处理本地部分为引号字符串、且后跟 RFC 5322 注释的地址时存在处理不当的问题,导致尾随的、由注释分隔的域名原子被保留在规范化后的地址中。例如,输入 会被解析为地址值 ,其中包含由字面空格分隔的、由攻击者可控的额外域名文本。在构建邮件信封时(src/mime-node 中的 envelope.to),该解析后的值未经过严格的收件人验证便被直接使用,

CVSS 5.3 · Medium EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1534 · Internal Spearphishing
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100699

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment
Source: CVE Program / CVE List V5
Vulnerability Description
Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For example, the input "user"@example.com(x)evil.com is parsed to the address value 'user@example.com evil.com', which contains additional attacker-controlled domain text separated by a literal space. This parsed value is used without further strict recipient validation when the message envelope is built (envelope.to in src/mime-node), so a malformed/ambiguous recipient address can be accepted and placed in the SMTP envelope. Whether this results in delivery to an unintended recipient on real SMTP servers has not been confirmed. The issue is a variant of the RFC 5322 comment parsing problem addressed in GHSA-cc9r-2j5m-2m83, affecting the separate quoted-local-part code path. Version 10.0.9 contains a fix.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nodemailer nodemailer 9.1.0 ~ 10.0.9 -

II. Public POCs for CVE-2026-100699

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100699

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100699 (1)

Other References for CVE-2026-100699 (1)

Same Patch Batch · nodemailer · 2026-09-26 · 4 CVEs total

CVE-2026-100700 7.5 HIGH nodemailer before 10.0.6 Denial of Service via addressparser
CVE-2026-100702 5.9 MEDIUM Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays
CVE-2026-100701 5.9 MEDIUM Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion

IV. Related Vulnerabilities

V. Comments for CVE-2026-100699

No comments yet


Leave a comment