CVE-2026-82853

NameCVE-2026-82853
DescriptionNodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-nodemailer (PTS)bookworm6.8.0+~6.4.6-1vulnerable
trixie6.10.0+~6.4.17-1+deb13u1vulnerable
forky, sid10.0.10+~8.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-nodemailersource(unstable)8.0.11+~8.0.1-1

Notes

[trixie] - node-nodemailer <no-dsa> (Minor issue)
[bookworm] - node-nodemailer <postponed> (Minor issue)
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g

Search for package or bug name: Reporting problems