Description
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Nodemailer before version 9.1.0 contains a quadratic time complexity flaw in its addressparser module. An attacker can trigger the flaw by submitting a single email with a crafted, comma‑separated address list that causes the parser to consume 100 % of the CPU, freezing the Node.js event loop and rendering the mail server unresponsive. The weakness is a classic denial‑of‑service attack that compromises availability of the affected application.

Affected Systems

All installations of the Nodemailer library with a version prior to 9.1.0 are vulnerable. The flaw is present in any environment that uses Node.js to process email messages through this library; it applies broadly to web applications, microservices, or email relay services that incorporate Nodemailer.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, suggesting high severity. Its EPSS score is below 1 %, indicating a low likelihood of widespread exploitation at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the attack vector is straightforward: a remote attacker sends an email containing a very large list of addresses, triggering the quadratic parse routine and exhausting CPU resources. Because the flaw exploits a public API, no privileged access or local code execution is required.

Generated by OpenCVE AI on September 17, 2026 at 23:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Nodemailer package to version 9.1.0 or later.
  • Configure your application to enforce a maximum number of recipients per message and reject or truncate address lists that exceed that threshold.
  • Implement monitoring or rate‑limiting on the Node.js event loop and process metrics to detect and mitigate unexpected CPU spikes caused by malicious address lists.

Generated by OpenCVE AI on September 17, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1050
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
Title Nodemailer before 9.1.0 Denial of Service via addressparser
First Time appeared Nodemailer
Nodemailer nodemailer
Weaknesses CWE-400
CPEs cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*
Vendors & Products Nodemailer
Nodemailer nodemailer
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nodemailer Nodemailer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:23:33.704Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92596

cve-icon Vulnrichment

Updated: 2026-09-17T13:23:26.299Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.557

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92596

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T21:47:00Z

Links: CVE-2026-92596 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:15:13Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop

  • CWE-400

    Uncontrolled Resource Consumption