Domain Allow-List Bypass in Nodemailer by Nodemailer Team
CVE-2026-92598

8.3HIGH

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92598?

The Nodemailer library prior to version 9.1.0 suffers from a flaw in how it handles internationalized domain names (IDN). By failing to properly apply UTS-46 normalization, Nodemailer allows attackers to create recipient email addresses with invisible characters or compatibility mappings. This can enable these addresses to circumvent domain allow-list checks, resulting in emails being delivered to domains controlled by malicious actors through the SMTP protocol. This poses significant risks to email integrity and security.

Affected Version(s)

nodemailer 0 < 9.1.0

nodemailer 9.1.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

e1abrador
.