{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anodemailernodemailer10.0.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodemailer:nodemailer:9.1.0:*:*:*:*:*:*:*","cpe:2.3:a:nodemailer:nodemailer:10.0.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-90776"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nodemailer (9.1.0-10.0.4)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Nodemailer"],"content_html":"\u003cp\u003eNodemailer versions 9.1.0 through 10.0.4 contain a vulnerability in the addressparser component that results in a quadratic time complexity condition when parsing email addresses containing RFC 5322 comments. An attacker can craft and submit specific email headers featuring deeply nested or complex comment-separated atoms. When the application attempts to process these headers, the addressparser library consumes excessive CPU cycles, effectively blocking the Node.js event loop for an extended period. Because Node.js operates on a single-threaded event loop, this resource exhaustion prevents the application from processing any other incoming requests, leading to a denial of service. This vulnerability is particularly critical for high-traffic mail servers or applications that rely on Nodemailer to ingest user-supplied email headers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial of service condition for the targeted Node.js application. By sending a single crafted request or a low-volume stream of crafted headers, an attacker can cause legitimate application traffic to fail, potentially disrupting business-critical communication systems or automated email processing workflows. No data exfiltration is associated with this vulnerability, but the loss of availability can significantly impact services relying on Nodemailer.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for development and security engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Nodemailer to version 10.0.5 or later, which contains the fix for the quadratic parsing issue.\u003c/li\u003e\n\u003cli\u003eAudit all applications utilizing Nodemailer to determine if user-controlled input is passed directly to email header fields processed by the library.\u003c/li\u003e\n\u003cli\u003eImplement input validation and length limits on email header fields to prevent processing of excessively large or malformed strings if upgrading is not immediately possible.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for high CPU usage spikes or event loop blockages occurring concurrently with incoming email requests to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T13:25:34Z","date_published":"2026-09-13T13:25:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nodemailer-dos/","summary":"Nodemailer versions 9.1.0 through 10.0.4 are vulnerable to a denial of service attack where malicious email headers trigger quadratic time complexity in the addressparser component, exhausting CPU resources.","title":"Nodemailer Addressparser Denial of Service via CVE-2026-90776","url":"https://feed.craftedsignal.io/briefs/2026-09-nodemailer-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nodemailer:nodemailer:10.0.4:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}