Denial of Service Vulnerability in Nodemailer Affects Node.js Applications
CVE-2026-100700
8.7HIGH
What is CVE-2026-100700?
The vulnerability found in Nodemailer versions prior to 10.0.6 involves a denial of service due to the quadratic backtracking behavior of the addressparser's fallback regex pattern. When an attacker sends specially crafted email header values with extensive whitespace-free runs, it can severely impact the Node.js event loop, causing significant service interruptions and unavailability for extended periods.
Affected Version(s)
nodemailer 0 < 10.0.6
nodemailer 10.0.6
