Nodemailer 5.0.0 至 10.0.1 版本使用了一个基于进程全局范围的 DNS 缓存,该缓存仅以 DNS 主机名作为键。然而,每个缓存条目还会存储调用方特定的 TLS servername。当两个直接 TLS/SMTPS 传输(secure: true)解析同一个非 IP 主机,但使用不同的 tls.servername 值时,缓存命中会返回第一个传输的 servername,并覆盖第二个传输中显式配置的值。这导致 Nodemailer 发送错误的 SNI(服务器名称指示)值,并针对错误的身份验证对端
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 5.0.0 ~ 10.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100700 | 7.5 HIGH | nodemailer before 10.0.6 Denial of Service via addressparser |
| CVE-2026-100702 | 5.9 MEDIUM | Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays |
| CVE-2026-100699 | 5.3 MEDIUM | Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment |
No comments yet