Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100701— Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion

Quick assessment

Affected
nodemailer nodemailer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nodemailer 5.0.0 至 10.0.1 版本使用了一个基于进程全局范围的 DNS 缓存,该缓存仅以 DNS 主机名作为键。然而,每个缓存条目还会存储调用方特定的 TLS servername。当两个直接 TLS/SMTPS 传输(secure: true)解析同一个非 IP 主机,但使用不同的 tls.servername 值时,缓存命中会返回第一个传输的 servername,并覆盖第二个传输中显式配置的值。这导致 Nodemailer 发送错误的 SNI(服务器名称指示)值,并针对错误的身份验证对端

CVSS 5.9 · Medium EPSS 0.11% · P1

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100701

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion
Source: CVE Program / CVE List V5
Vulnerability Description
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host with different tls.servername values, the first transport's servername is returned on the cache hit and overwrites the second transport's explicitly configured value, so Nodemailer sends the wrong SNI value and validates the peer certificate against the wrong identity. In multi-tenant services or SNI-routed SMTP gateways, an attacker who can prime the cache can cause a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate even with rejectUnauthorized: true, disclosing the victim's SMTP credentials. Fixed in 10.0.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nodemailer nodemailer 5.0.0 ~ 10.0.2 -

II. Public POCs for CVE-2026-100701

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100701

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100701 (1)

Other References for CVE-2026-100701 (1)

Same Patch Batch · nodemailer · 2026-09-26 · 4 CVEs total

CVE-2026-100700 7.5 HIGH nodemailer before 10.0.6 Denial of Service via addressparser
CVE-2026-100702 5.9 MEDIUM Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays
CVE-2026-100699 5.3 MEDIUM Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment

IV. Related Vulnerabilities

V. Comments for CVE-2026-100701

No comments yet


Leave a comment