Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a larg
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 0 ~ 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92598 | 6.5 MEDIUM | Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass |
| CVE-2026-92597 | 6.5 MEDIUM | Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment |
| CVE-2026-92595 | 5.9 MEDIUM | Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent |
No comments yet