PT-2026-94113 · Npm · Nodemailer

·

CVE-2026-92596

·

Published

2026-09-01

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Nodemailer versions prior to 9.1.0
Description Nodemailer contains a quadratic time complexity issue in its addressparser component. When parsing a list of comma-separated addresses, the parser uses Array.prototype.concat to accumulate results, which causes the CPU consumption to grow proportionally to the square of the input length. This behavior blocks the single-threaded Node.js event loop, leading to 100% CPU usage and freezing the process, which results in a denial of service for all other requests.
This issue can be triggered via structured-address headers such as To, Cc, Bcc, From, or Reply-To, or by directly using the exported addressparser module. For example, an address value of approximately 1.5 MB can freeze the process for 25 to 30 seconds.
Recommendations Update Nodemailer to version 9.1.0 or later. As a temporary mitigation, restrict the length of user-supplied address strings or limit the number of recipients allowed in email headers before they are processed by the parser.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14922
CVE-2026-92596
GHSA-2X7J-588G-CCC2

Affected Products

Nodemailer