Vendor
Nodemailer Addressparser Denial of Service via CVE-2026-90776
1 TTP 1 CVENodemailer versions 9.1.0 through 10.0.4 are vulnerable to a denial of service attack where malicious email headers trigger quadratic time complexity in the addressparser component, exhausting CPU resources.
Nodemailer SSRF and Arbitrary File Read Vulnerability
3 TTPs 1 CVENodemailer versions before 9.0.1 fail to enforce security flags when processing message-level raw options, allowing authenticated attackers to perform SSRF and read arbitrary files.
Nodemailer MailComposer Security Bypass Vulnerability
3 TTPsNodemailer version 9.0.0 and earlier fails to enforce security flags when using the raw message option, allowing attackers to bypass file and URL access restrictions for arbitrary file read or SSRF.
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF
2 rules 3 TTPs 2 IOCsNodemailer versions up to 9.0.0 are vulnerable to arbitrary local file read and full-response Server-Side Request Forgery (SSRF) when handling untrusted input for the message-level `raw` option, bypassing intended security flags and allowing sensitive content to be exfiltrated via an attacker-controlled recipient.