CVE-2026-90776
EUVD-2026-7700013.09.2026, 12:17
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nodemailer | nodemailer | 9.1.0 ≤ 𝑥 < 10.0.5 | CNA |
Debian Releases
References