PT-2026-94114 · Npm · Nodemailer

·

CVE-2026-92597

·

Published

2026-09-08

·

Updated

2026-09-16

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Nodemailer versions 6.9.16 through 9.0.x
Description Nodemailer mis-parses RFC 5322 comments within email addresses. In the lib/addressparser component, when a comment is closed immediately before a non-break character, the tokenizer concatenates the surrounding atoms instead of treating the comment as folding whitespace (CFWS) that should terminate the domain. For example, an address like user@good-corp.com(x)evil.com is interpreted as good-corp.comevil.com rather than good-corp.com.
This creates an interpretation conflict where an application using a strict RFC 5322 parser or a naive prefix/substring allow-list for domain validation may be deceived into believing an address is legitimate, while Nodemailer delivers the email to an attacker-controlled domain. This affects both the SMTP envelope RCPT TO and the To:/From: headers. The root cause is located in the handleAddress function and the tokenizer's handling of the noBreak property in lib/addressparser/index.js.
Recommendations Update Nodemailer to version 9.1.0 or later. As a temporary mitigation, avoid using naive prefix or substring allow-lists for email domain validation and ensure that any strict RFC 5322 parser used for validation is configured to inspect and reject parse defects.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92597
GHSA-CC9R-2J5M-2M83

Affected Products

Nodemailer