{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nodemailer--10.0.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100700"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["nodemailer (\u003c 10.0.6)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Nodemailer"],"content_html":"\u003cp\u003eNodemailer versions prior to 10.0.6 contain a Regular Expression Denial of Service (ReDoS) vulnerability in the addressparser component. The flaw exists within a free-text fallback regular expression pattern that exhibits quadratic backtracking behavior when processing specific input strings. By submitting crafted email header values containing long sequences of non-whitespace characters, an attacker can force the regex engine to enter a state of extreme computational complexity. Because Node.js operates on a single-threaded event loop, this excessive processing blocks the event loop for tens of seconds, rendering the affected application unresponsive and causing service unavailability. This vulnerability is particularly critical for applications that process user-supplied email data or headers without validation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial of Service (DoS) condition, forcing the Node.js application to become unavailable by blocking its primary event loop. This can impact any service relying on Nodemailer for email processing or header parsing, potentially leading to widespread outages in applications that process external email inputs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the nodemailer package to version 10.0.6 or later immediately to incorporate the fixed addressparser regex logic.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing Nodemailer to identify input vectors where user-controlled email header data is passed to the library.\u003c/li\u003e\n\u003cli\u003eImplement length constraints on all input strings that are subsequently passed to email header parsing functions to mitigate the risk of triggering catastrophic backtracking.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T15:12:59Z","date_published":"2026-09-26T15:12:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nodemailer-redos/","summary":"Nodemailer versions before 10.0.6 are vulnerable to a Regular Expression Denial of Service (ReDoS) in the addressparser component, allowing attackers to block the Node.js event loop via crafted email headers.","title":"CVE-2026-100700 Denial of Service in Nodemailer","url":"https://feed.craftedsignal.io/briefs/2026-09-nodemailer-redos/"}],"language":"en","title":"CraftedSignal Threat Feed - Nodemailer (\u003c 10.0.6)","version":"https://jsonfeed.org/version/1.1"}