CRLF Injection Vulnerability in Nodemailer by Nodemailer
CVE-2026-82661
5.3MEDIUM
What is CVE-2026-82661?
The Nodemailer email library, prior to version 8.0.9, has a vulnerability that allows attackers to exploit improper sanitization of carriage return and line feed characters in list comment fields. This can lead to the injection of arbitrary message headers, which could alter the behavior of mail clients and distort the intended message semantics. By manipulating the list.*.comment parameters, an unauthorized user could introduce additional headers in RFC822 formatted messages, potentially compromising email integrity and security.
Affected Version(s)
nodemailer 0 < 8.0.9
nodemailer 8.0.9
