PT-2026-99373 · Npm · Nodemailer

·

CVE-2026-100702

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nodemailer versions prior to 10.0.2
Description Improper flattening of deeply nested arrays in recipient fields such as to, cc, and bcc can lead to stack exhaustion. An attacker can provide a deeply nested JSON recipient array that triggers a recursive Array.toString() conversion, which exhausts the call stack and terminates the Node.js process.
Recommendations Update to version 10.0.2 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100702
GHSA-8VVX-RFF5-P5RQ

Affected Products

Nodemailer