Domain Allow-List Bypass in Nodemailer by Nodemailer Team
CVE-2026-92598
8.3HIGH
What is CVE-2026-92598?
The Nodemailer library prior to version 9.1.0 suffers from a flaw in how it handles internationalized domain names (IDN). By failing to properly apply UTS-46 normalization, Nodemailer allows attackers to create recipient email addresses with invisible characters or compatibility mappings. This can enable these addresses to circumvent domain allow-list checks, resulting in emails being delivered to domains controlled by malicious actors through the SMTP protocol. This poses significant risks to email integrity and security.
Affected Version(s)
nodemailer 0 < 9.1.0
nodemailer 9.1.0
