Nodemailer
31 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Nodemailer, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Nodemailer CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 4 |
| 2026-07 | 0 |
| 2026-08 | 7 |
| 2026-09 | 13 |
Severity
How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High7
- Medium12
Latest CVEs
The 15 most recently published vulnerabilities affecting Nodemailer.
- CVE-2026-100702Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays5.9
- CVE-2026-100701Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion5.9
- CVE-2026-100700nodemailer before 10.0.6 Denial of Service via addressparser7.5
- CVE-2026-100699Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment5.3
- CVE-2026-92598Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass6.5
- CVE-2026-92597Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment6.5
- CVE-2026-92595Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent5.9
- CVE-2026-92596Nodemailer before 9.1.0 Denial of Service via addressparser7.5
- CVE-2026-90776Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing7.5
- GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain—
- GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list—
- GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain—
- GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature—
- CVE-2026-82854Nodemailer before 8.0.3 SMTP Command Injection via envelope.size9.8
- CVE-2026-82853Nodemailer before 8.0.5 SMTP Command Injection via CRLF4.9
Product grouping is registry-driven, with AI assist and human review. How it works