HIGH
CVE-2026-92596
CVSS
7.5
Description
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.45%
Probability of exploitation in next 30 days
38.7th percentile
References
https://github.com/nodemailer/nodemailer/commit/34da642
https://github.com/nodemailer/nodemailer/commit/7cc38af
https://github.com/nodemailer/nodemailer/commit/83b8c48
https://github.com/nodemailer/nodemailer/commit/9116da9
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-denial-of-service-via-addressparser
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.