Skip to content
Threat Feed

Vendor

Nodemailer

4 briefs RSS
low advisory

Nodemailer Addressparser Denial of Service via CVE-2026-90776

Nodemailer versions 9.1.0 through 10.0.4 are vulnerable to a denial of service attack where malicious email headers trigger quadratic time complexity in the addressparser component, exhausting CPU resources.

Nodemailer
1t 1c
high advisory

Nodemailer SSRF and Arbitrary File Read Vulnerability

Nodemailer versions before 9.0.1 fail to enforce security flags when processing message-level raw options, allowing authenticated attackers to perform SSRF and read arbitrary files.

nodemailer +1 vulnerability ssrf file-access smtp-injection
3t 1c
high advisory

Nodemailer MailComposer Security Bypass Vulnerability

Nodemailer version 9.0.0 and earlier fails to enforce security flags when using the raw message option, allowing attackers to bypass file and URL access restrictions for arbitrary file read or SSRF.

Nodemailer webapps ssrf file-read security-bypass
3t
high advisory

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF

Nodemailer versions up to 9.0.0 are vulnerable to arbitrary local file read and full-response Server-Side Request Forgery (SSRF) when handling untrusted input for the message-level `raw` option, bypassing intended security flags and allowing sensitive content to be exfiltrated via an attacker-controlled recipient.

Nodemailer <= 9.0.0 ssrf file-read nodemailer nodejs javascript supply-chain
2r 3t 2i