Description
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
Published: 2026-09-16
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized email delivery and domain spoofing
Action: Immediate Patch
AI Analysis

Impact

Nodemailer versions earlier than 9.1.0 fail to perform the required UTS‑46 normalization when encoding international domain names, which causes the domain resolver to compute a Punycode A‑label that differs from standards‑compliant parsers. This flaw allows an attacker to embed invisible characters or compatibility mappings into a recipient address that passes Nodemailer’s allow‑list checks, yet the underlying SMTP transaction is directed to an attacker‑controlled domain. The result is that an email appears to be sent to a legitimate address but is actually delivered to a hostile domain, enabling spoofing or phishing campaigns. The weakness is an authentication or authorization bypass, identified as CWE‑436.

Affected Systems

The vulnerability exists in the Nodemailer npm package for Node.js. Any installation of Nodemailer older than version 9.1.0 is affected. Systems that rely on these older releases to send outbound email—whether in production, staging, or test environments—are at risk.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity. The EPSS score is less than 1 percent, reflecting currently low published exploitation activity, and the flaw is not listed in the CISA KEV catalog. The attack does not require elevated privileges; the likely attack vector is via crafted email addresses supplied to the Nodemailer instance, typically through a web application that sends email. If an attacker can influence the recipient data, they can inject the malformed address and trigger the bypass for domain resolution.

Generated by OpenCVE AI on September 17, 2026 at 22:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Nodemailer to version 9.1.0 or later, where the UTS‑46 normalization bug is fixed.
  • If upgrading is not immediately feasible, enforce strict UTS‑46 normalization on all recipient addresses before passing them to Nodemailer, removing or mapping invisible and compatibility characters.
  • Validate all email addresses against a strict whitelist or disable the library’s allow‑list entirely to prevent legacy or insufficiently sanitized input from reaching the domain resolver.

Generated by OpenCVE AI on September 17, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-289
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
Title Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass
First Time appeared Nodemailer
Nodemailer nodemailer
Weaknesses CWE-436
CPEs cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*
Vendors & Products Nodemailer
Nodemailer nodemailer
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Nodemailer Nodemailer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:43:20.281Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92598

cve-icon Vulnrichment

Updated: 2026-09-17T14:40:27.336Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.840

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92598

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T21:47:02Z

Links: CVE-2026-92598 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-289

    Authentication Bypass by Alternate Name

  • CWE-436

    Interpretation Conflict