nodemailer vulnerability

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.

Published 13 Sep 2026Updated 13 Sep 20266 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.