CVE-2026-92596
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 16, 2026
Vendor
unknown
Description
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
References
- https://github.com/nodemailer/nodemailer/commit/34da642
- https://github.com/nodemailer/nodemailer/commit/7cc38af
- https://github.com/nodemailer/nodemailer/commit/83b8c48
- https://github.com/nodemailer/nodemailer/commit/9116da9
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2