CRLF Injection Vulnerability in Nodemailer by Nodemailer
CVE-2026-82661

5.3MEDIUM

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82661?

The Nodemailer email library, prior to version 8.0.9, has a vulnerability that allows attackers to exploit improper sanitization of carriage return and line feed characters in list comment fields. This can lead to the injection of arbitrary message headers, which could alter the behavior of mail clients and distort the intended message semantics. By manipulating the list.*.comment parameters, an unauthorized user could introduce additional headers in RFC822 formatted messages, potentially compromising email integrity and security.

Affected Version(s)

nodemailer 0 < 8.0.9

nodemailer 8.0.9

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
dungNHVhust
.