| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-90776 | vulnerable | vulnerable (no DSA) | vulnerable | fixed | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ... |
| CVE-2026-82854 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.4 is vulnerable to SMTP command injection throug ... |
| CVE-2026-82853 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer versions before 8.0.5 contain an SMTP command injection vul ... |
| CVE-2026-82662 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ... |
| CVE-2026-82661 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ... |
| CVE-2026-82660 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ... |
| CVE-2026-82659 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ... |
| CVE-2025-14874 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | A flaw was found in Nodemailer. This vulnerability allows a denial of ... |
| CVE-2025-13033 | vulnerable (no DSA) | fixed | fixed | fixed | A vulnerability was identified in the email parsing library due to imp ... |
| CVE-2024-58379 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | nodemailer before 6.9.9 contains a regular expression denial of servic ... |