| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-100702 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer before 10.0.2 fails to properly flatten deeply nested array ... |
| CVE-2026-100701 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cach ... |
| CVE-2026-100700 | vulnerable | vulnerable (no DSA) | fixed | fixed | nodemailer before 10.0.6 contains a denial of service vulnerability in ... |
| CVE-2026-100699 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 an ... |
| CVE-2026-92598 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ... |
| CVE-2026-92597 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments ... |
| CVE-2026-92596 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerabi ... |
| CVE-2026-92595 | vulnerable | vulnerable (no DSA) | fixed | fixed | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ... |
| CVE-2026-90776 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ... |
| CVE-2026-82854 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.4 is vulnerable to SMTP command injection throug ... |
| CVE-2026-82853 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer versions before 8.0.5 contain an SMTP command injection vul ... |
| CVE-2026-82662 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ... |
| CVE-2026-82661 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ... |
| CVE-2026-82660 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ... |
| CVE-2026-82659 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ... |
| CVE-2025-14874 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | A flaw was found in Nodemailer. This vulnerability allows a denial of ... |
| CVE-2025-13033 | vulnerable (no DSA) | fixed | fixed | fixed | A vulnerability was identified in the email parsing library due to imp ... |
| CVE-2024-58379 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | nodemailer before 6.9.9 contains a regular expression denial of servic ... |