Npm · Nodemailer · CVE-2026-100701
**Name of the Vulnerable Software and Affected Versions**
Nodemailer versions 5.0.0 through 10.0.1
**Description**
Nodemailer uses a process-global DNS cache keyed only by the DNS host, but stores the caller-specific TLS servername within each entry. When two direct TLS/SMTPS transports configured with `secure: true` resolve the same non-IP host using different `tls.servername` values, the first transport's servername is returned during a cache hit. This overwrites the second transport's configured value, causing Nodemailer to send an incorrect Server Name Indication (SNI) value and validate the peer certificate against the wrong identity. In multi-tenant services or SNI-routed SMTP gateways, an attacker capable of priming the cache can force a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate, even when `rejectUnauthorized: true` is set, potentially disclosing the victim's SMTP credentials.
**Recommendations**
Update Nodemailer to version 10.0.2.