Denial of Service Vulnerability in Nodemailer SMTP Server Products
CVE-2026-38728

7.5HIGH

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
15 May 2026

What is CVE-2026-38728?

A vulnerability in Nodemailer’s SMTP Server allows attackers to exploit the SMTPStream._write method in lib/smtp-stream.js, which can lead to denial of service. This vulnerability could potentially cause significant disruption to email services by preventing the server from processing requests efficiently. It is crucial for users to upgrade to version 3.18.3 or later to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.