Medium severity5.9NVD Advisory· Published Sep 26, 2026
CVE-2026-100702
CVE-2026-100702
Description
Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.
Affected products
1- Range: <10.0.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.