在 9.1.0 之前,Nodemailer 在编码国际域名时未能应用 UTS-46 规范化,导致域名解析器计算出的 Punycode A-label 与符合标准的解析器结果不一致。攻击者可以构造包含不可见字符或兼容性映射的收件人地址,这些地址能够绕过域名白名单检查,并通过 SMTP 被投递到由攻击者控制的域名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 0 ~ 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92596 | 7.5 HIGH | Nodemailer before 9.1.0 Denial of Service via addressparser |
| CVE-2026-92597 | 6.5 MEDIUM | Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment |
| CVE-2026-92595 | 5.9 MEDIUM | Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent |
No comments yet