GHSA-v554-hhrr-96v5HighCVSS 7.5

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.

🔗 References (8)