Npm · Nodemailer · CVE-2026-90776
**Name of the Vulnerable Software and Affected Versions**
Nodemailer versions 9.1.0 through 10.0.4
**Description**
The `addressparser` component contains an algorithmic complexity issue when parsing email addresses that include RFC 5322 comments. A remote attacker can craft malicious email headers using comment-separated atoms to trigger quadratic time complexity, which consumes excessive CPU resources and blocks the Node.js event loop for several seconds, resulting in a denial of service.
**Recommendations**
Update to version 10.0.5 or later.