Nodemailer 10.0.2 之前的版本无法正确扁平化收件人字段(如 to、cc 和 bcc)中的深层嵌套数组,从而允许攻击者导致堆栈耗尽。攻击者可以提供深层嵌套的 JSON 收件人数组,触发递归的 Array.toString() 转换,耗尽调用栈并导致 Node.js 进程终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 0 ~ 10.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100700 | 7.5 HIGH | nodemailer before 10.0.6 Denial of Service via addressparser |
| CVE-2026-100701 | 5.9 MEDIUM | Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion |
| CVE-2026-100699 | 5.3 MEDIUM | Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment |
No comments yet