Description
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as user@good-corp.com(x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registrable domain comevil.com, which an attacker can register) and used for both the SMTP envelope (RCPT TO) and the emitted To:/From: headers, while a conformant RFC 5322 parser terminates the domain at the comment and reads good-corp.com. An application that validates the recipient domain with a strict RFC 5322 parser (without inspecting parse defects) or a naive prefix/substring allow-list and then hands the raw address to Nodemailer can be induced to deliver mail to a domain the attacker controls. Fixed in 9.1.0.
Published: 2026-09-16
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized email delivery to attacker–controlled domains
Action: Immediate Patch
AI Analysis

Impact

Nodemailer mis‑parses RFC 5322 comments in email addresses, allowing a crafted address such as user@good‑corp.com(x)evil.com to be interpreted as the single domain good‑corp.comevil.com, which an attacker can register. The library then uses this domain for both the SMTP envelope and email headers, leading to delivery of mail to an attacker‑controlled zone. This can facilitate phishing, spoofing, and spam without explaining the undesired domain to the user. The flaw corresponds to both CWE‑436 (Failure to Clarify Domain) and CWE‑1286 (Improper Handling of Comments).

Affected Systems

The vulnerability affects Nodemailer library versions from 6.9.16 through 9.0.9 inclusive. The fix is delivered in Nodemailer 9.1.0 and later. No other products or platforms are listed.

Risk and Exploitability

With a CVSS score of 8.3, the issue is considered high severity. EPSS indicates a very low current exploitation probability (<1%), and the vulnerability is not in the CISA KEV catalog. An attacker can exploit it by submitting a maliciously crafted recipient address to any application that uses Nodemailer and performs weak or no domain validation, usually without elevated privileges. The attack would result in mail being routed to the attacker’s domain and may bypass normal spam controls. The flaw involves both improper domain clarification (CWE‑436) and improper handling of comments (CWE‑1286).

Generated by OpenCVE AI on September 23, 2026 at 01:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Nodemailer to version 9.1.0 or later.
  • Implement RFC 5322 compliant validation that rejects addresses containing invalid or unexpected comments, or enforce a strict domain allow‑list.
  • Monitor outgoing SMTP traffic for unexpected recipient domains and restrict Nodemailer usage to trusted internal services.

Generated by OpenCVE AI on September 23, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as user@good-corp.com(x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registrable domain comevil.com, which an attacker can register) and used for both the SMTP envelope (RCPT TO) and the emitted To:/From: headers, while a conformant RFC 5322 parser terminates the domain at the comment and reads good-corp.com. An application that validates the recipient domain with a strict RFC 5322 parser (without inspecting parse defects) or a naive prefix/substring allow-list and then hands the raw address to Nodemailer can be induced to deliver mail to a domain the attacker controls. Fixed in 9.1.0.
Title Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment
First Time appeared Nodemailer
Nodemailer nodemailer
Weaknesses CWE-436
CPEs cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*
Vendors & Products Nodemailer
Nodemailer nodemailer
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Nodemailer Nodemailer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:23:22.319Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92597

cve-icon Vulnrichment

Updated: 2026-09-17T19:17:09.411Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.700

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92597

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T21:47:01Z

Links: CVE-2026-92597 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input

  • CWE-436

    Interpretation Conflict