Vendor
Nodemailer vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in Nodemailer: 3 in the last 7 days and 19 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100702, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 3
- Last 90 days
- 19
- Critical, all time
- 1
- Exploited in the wild
- 0
About Nodemailer
Nodemailer is the developer of a module for Node.js applications to allow easy email sending.
Nodemailer technologies
Latest Nodemailer vulnerabilities
- CVE-2026-100702: Nodemailer stack exhaustion in recipient array flatteningmediumCVSS 5.9
- CVE-2026-100701: Nodemailer TLS servername cache confusion vulnerabilitymediumCVSS 5.9
- CVE-2026-100700: nodemailer addressparser regular expression denial of servicehighCVSS 7.5
- CVE-2026-92598: Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-92597: Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-92596: Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows…highCVSS 7.5EPSS 0.8%
- CVE-2026-92595: Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and…mediumCVSS 5.9EPSS 0.3%
- CVE-2026-90776: Nodemailer quadratic time complexity in address parserhighCVSS 7.5EPSS 0.7%
- Nodemailer quadratic time complexity in address parserhighCVSS 7.5
- Nodemailer email address validation bypass in RFC 5322 comment parsingmediumCVSS 6.5
- Nodemailer resolveContent sandbox bypass in legacy signaturemediumCVSS 5.9
- Nodemailer message-level raw option SSRF and file readlowCVSS 3.1
- CVE-2026-82854: Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an…criticalCVSS 9.8EPSS 2.0%
- CVE-2026-82853: Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in…mediumCVSS 4.9EPSS 1.0%
- CVE-2026-82662: Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false…mediumCVSS 6.5EPSS 0.2%
- CVE-2026-82661: Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-82660: Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-82659: nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing…highCVSS 7.1EPSS 0.4%
- CVE-2024-58379: nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls…mediumCVSS 5.3EPSS 0.3%
- Nodemailer sandbox bypass via raw message optionhighCVSS 7.1
- Nodemailer CRLF injection in List-* header commentsmediumCVSS 5.4
- Nodemailer access control bypass in jsonTransportmediumCVSS 5.4
- Nodemailer improper TLS certificate validation in OAuth2 fetchmediumCVSS 6.5
- CVE-2026-38728: Nodemailer smtp-server Denial of Service via memory exhaustionhighCVSS 7.5EPSS 0.8%
- CVE-2025-14874: Nodemailer addressparser denial of service via recursive callshighCVSS 7.5EPSS 0.6%
Most severe Nodemailer vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-82854: Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an…criticalCVSS 9.8EPSS 2.0%
- CVE-2026-92596: Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows…highCVSS 7.5EPSS 0.8%
- CVE-2026-38728: Nodemailer smtp-server Denial of Service via memory exhaustionhighCVSS 7.5EPSS 0.8%
- CVE-2026-90776: Nodemailer quadratic time complexity in address parserhighCVSS 7.5EPSS 0.7%
- CVE-2025-14874: Nodemailer addressparser denial of service via recursive callshighCVSS 7.5EPSS 0.6%
- CVE-2025-13033: Nodemailer improper email parsing in addressparserhighCVSS 7.5EPSS 0.5%
- CVE-2026-100700: nodemailer addressparser regular expression denial of servicehighCVSS 7.5
- Nodemailer quadratic time complexity in address parserhighCVSS 7.5
- Nodemailer interpretation conflict in email address parsinghighCVSS 7.5
- CVE-2026-82659: nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing…highCVSS 7.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 8 | 1 | |
| 7 Sep 2026 | 4 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 3 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/nodemailer.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Nodemailer vulnerabilities", https://junglewise.ai/threats/vendors/nodemailer, 26 September 2026.