CVE-2026-100700

NameCVE-2026-100700
Descriptionnodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-nodemailer (PTS)bookworm6.8.0+~6.4.6-1vulnerable
trixie6.10.0+~6.4.17-1+deb13u1vulnerable
forky10.0.10+~8.0.1-1fixed
sid10.0.10+~8.0.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-nodemailersource(unstable)10.0.10+~8.0.1-1

Notes

https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
Fixed by: https://github.com/nodemailer/nodemailer/commit/437d7fc47403df176bc39271641541b7a9bce102 (v10.0.6)

Search for package or bug name: Reporting problems