CVE Tools

Nodemailer

31 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nodemailer, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Nodemailer CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nodemailer CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-121
2026-010
2026-020
2026-031
2026-041
2026-050
2026-064
2026-070
2026-087
2026-0913

Severity

How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High735%
  • Medium1260%

Latest CVEs

The 15 most recently published vulnerabilities affecting Nodemailer.

  1. CVE-2026-100702Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays5.9
  2. CVE-2026-100701Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion5.9
  3. CVE-2026-100700nodemailer before 10.0.6 Denial of Service via addressparser7.5
  4. CVE-2026-100699Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment5.3
  5. CVE-2026-92598Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass6.5
  6. CVE-2026-92597Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment6.5
  7. CVE-2026-92595Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent5.9
  8. CVE-2026-92596Nodemailer before 9.1.0 Denial of Service via addressparser7.5
  9. CVE-2026-90776Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing7.5
  10. GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain—
  11. GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list—
  12. GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain—
  13. GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature—
  14. CVE-2026-82854Nodemailer before 8.0.3 SMTP Command Injection via envelope.size9.8
  15. CVE-2026-82853Nodemailer before 8.0.5 SMTP Command Injection via CRLF4.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store