Vulnerabilities in nodemailer
14 resultsVexday analysis
Nodemailer apresenta 2 vulnerabilidades registradas, nenhuma com exploração ativa conhecida ou classificação crítica, indicando risco controlado. A fraqueza dominante (CWE-1286) não representa ameaça imediata, e a ausência de divulgações recentes sugere que o fornecedor não é alvo prioritário de pesquisadores de segurança no momento.
CVE-2026-82854CRITICALNodemailer before 8.0.3 SMTP Command Injection via envelope.sizeEPSS 1.1%CVE-2026-82853MEDIUMNodemailer before 8.0.5 SMTP Command Injection via CRLFEPSS 0.7%CVE-2025-13033HIGHNodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflictEPSS 0.5%CVE-2025-14874HIGHNodemailer: nodemailer: denial of service via crafted email address headerEPSS 0.5%CVE-2026-90776HIGHNodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address ParsingEPSS 0.5%CVE-2026-92596HIGHNodemailer before 9.1.0 Denial of Service via addressparserEPSS 0.5%CVE-2024-58379MEDIUMnodemailer before 6.9.9 ReDoS via attachDataUrls parameterEPSS 0.3%CVE-2026-92598HIGHNodemailer before 9.1.0 IDN/Punycode Domain Allow-list BypassEPSS 0.3%CVE-2026-92597HIGHNodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 CommentEPSS 0.3%CVE-2026-82659HIGHnodemailer before 9.0.1 File Read and SSRF via raw optionEPSS 0.3%CVE-2026-92595MEDIUMNodemailer before 9.1.1 Security Sandbox Bypass via resolveContentEPSS 0.2%CVE-2026-82661MEDIUMNodemailer CRLF Injection via List-* Header CommentsEPSS 0.2%CVE-2026-82660MEDIUMNodemailer jsonTransport bypasses disableFileAccess and disableUrlAccessEPSS 0.2%CVE-2026-82662HIGHNodemailer before 8.0.8 TLS Certificate Validation BypassEPSS 0.1%