High severity7.5NVD Advisory· Published Sep 16, 2026
CVE-2026-92596
CVE-2026-92596
Description
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.1.0
Patches
Vulnerability mechanics
References
6- github.com/nodemailer/nodemailer/commit/34da642nvd
- github.com/nodemailer/nodemailer/commit/7cc38afnvd
- github.com/nodemailer/nodemailer/commit/83b8c48nvd
- github.com/nodemailer/nodemailer/commit/9116da9nvd
- github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2nvd
- www.vulncheck.com/advisories/nodemailer-before-9.1.0-denial-of-service-via-addressparsernvd
News mentions
0No linked articles in our index yet.