Denial of Service Vulnerability in Nodemailer by Nodemailer
CVE-2026-90776

8.7HIGH

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
13 September 2026

What is CVE-2026-90776?

Nodemailer versions 9.1.0 through 10.0.4 are impacted by a denial of service issue due to a quadratic time complexity vulnerability in the addressparser component. This flaw allows attackers to create malicious email headers, which, when processed, can exhaust CPU resources and block the Node.js event loop for an extended period. As a result, the system may become unresponsive, impacting service availability and performance.

Affected Version(s)

nodemailer 9.1.0 < 10.0.5

nodemailer 10.0.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mmadersbacher
.