VYPR
patchPublished Sep 26, 2026· Updated Sep 28, 2026· 1 source

Nodemailer: Four Vulnerabilities Including DoS and Stack Exhaustion Disclosed Together

Key findings • Four Nodemailer vulnerabilities disclosed on September 26, 2026, impacting versions prior to 10.0.9. • High-severity CVE-2026-100700 allows denial of service via regex backtrac…

Key findings

  • Four Nodemailer vulnerabilities disclosed on September 26, 2026, impacting versions prior to 10.0.9.
  • High-severity CVE-2026-100700 allows denial of service via regex backtracking.
  • CVE-2026-100702 enables stack exhaustion through deeply nested recipient arrays.
  • CVE-2026-100701 suffers from an insecure process-global DNS cache.
  • CVE-2026-100699 mishandles address parsing with quoted local-parts and comments.
  • All issues fixed in Nodemailer version 10.0.9.

On September 26, 2026, a batch of four vulnerabilities was disclosed for the Nodemailer npm package, affecting versions prior to 10.0.2, 10.0.1, 10.0.6, and 10.0.9 respectively. These vulnerabilities, with severities ranging from Medium to High, primarily impact the package's handling of recipient fields, DNS caching, address parsing, and regular expression processing, potentially leading to denial-of-service conditions and other issues.

One of the most critical vulnerabilities, CVE-2026-100700, rated High with a CVSSv3 score of 7.5, resides in the addressparser's free-text fallback regular expression. This pattern exhibits quadratic backtracking, meaning specially crafted email header values with long whitespace-free sequences can cause the Node.js event loop to hang for extended periods, leading to a denial of service.

CVE-2026-100702, a Medium severity vulnerability (CVSSv3 5.9), arises from Nodemailer's failure to properly flatten deeply nested arrays within recipient fields like 'to', 'cc', and 'bcc'. Attackers can exploit this by providing a deeply nested JSON recipient array, which triggers a recursive Array.toString() conversion, ultimately exhausting the call stack and terminating the application.

Another Medium severity issue, CVE-2026-100701 (CVSSv3 5.9), involves a process-global DNS cache that is keyed only by the DNS host. When two direct TLS/SMTPS transports resolve the same non-IP host but with different tls.servername values, the first transport's cached DNS information is incorrectly used by the second, potentially leading to connection failures or unexpected behavior.

Finally, CVE-2026-100699, a Medium severity vulnerability (CVSSv3 5.3), affects the address parser in Nodemailer versions 9.1.0 through 10.0.1. It mishandles addresses where the local-part is a quoted string followed by RFC 5322 comments. This can result in trailing comment-separated domain atoms being retained in the normalized address, which could lead to incorrect email routing or parsing errors.

All disclosed vulnerabilities have been addressed in Nodemailer version 10.0.9. Users are strongly advised to update to this latest version to mitigate these risks. The timely disclosure and patching of these issues by the Nodemailer team underscore the importance of regular security updates for npm packages.

The range of vulnerabilities, from stack exhaustion to denial-of-service and incorrect address parsing, highlights the diverse attack surface that can be present even in well-established libraries. Maintaining up-to-date dependencies is crucial for Node.js application security.

Nodemailer versions prior to 10.0.2, 10.0.1, 10.0.6, and 10.0.9 are affected by these vulnerabilities. The patched version is 10.0.9. The vulnerabilities were disclosed on September 26, 2026. Key vulnerabilities include stack exhaustion, denial of service via regex backtracking, and incorrect DNS caching. CVE-2026-100700 is a high-severity denial-of-service vulnerability due to regex backtracking. CVE-2026-100702 allows for stack exhaustion by exploiting nested array handling. CVE-2026-100701 involves an insecure DNS cache keyed only by host. CVE-2026-100699 mishandles quoted local-parts in addresses with comments.

Synthesized by Vypr AI