PT-2026-99372 · Npm · Nodemailer

·

CVE-2026-100701

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nodemailer versions 5.0.0 through 10.0.1
Description Nodemailer uses a process-global DNS cache keyed only by the DNS host, but stores the caller-specific TLS servername within each entry. When two direct TLS/SMTPS transports configured with secure: true resolve the same non-IP host using different tls.servername values, the first transport's servername is returned during a cache hit. This overwrites the second transport's configured value, causing Nodemailer to send an incorrect Server Name Indication (SNI) value and validate the peer certificate against the wrong identity. In multi-tenant services or SNI-routed SMTP gateways, an attacker capable of priming the cache can force a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate, even when rejectUnauthorized: true is set, potentially disclosing the victim's SMTP credentials.
Recommendations Update Nodemailer to version 10.0.2.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100701
GHSA-6VJ9-MWQ6-2F5V

Affected Products

Nodemailer