Denial of Service Vulnerability in Nodemailer by Nodemailer Team
CVE-2026-92596

8.7HIGH

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92596?

Nodemailer versions prior to 9.1.0 are susceptible to a denial of service vulnerability in the addressparser component. Attackers can exploit this weakness by sending a specially crafted email that includes a large comma-separated list of addresses. This can lead to significant CPU consumption, causing the Node.js event loop to become blocked for extensive periods and effectively freezing the application. Users are urged to upgrade to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

nodemailer 0 < 9.1.0

nodemailer 9.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

e1abrador
.