These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-92598 is a vulnerability in Nodemailer before version 9.1.0, where the library fails to apply UTS-46 normalization when encoding international domain names. This causes the domain resolver to compute a different Punycode A-label than standards-compliant parsers, allowing attackers to craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks b [truncated]
CVE-2026-92597 Nodemailer Domain Validation Bypass. Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses, potentially leading to domain validation bypasses. This vulnerability allows an attacker to manipulate the recipient address to deliver mail to a domain under their control. Defenders responsible for email delivery configurations, especially those using Nodemailer, [truncated]
CVE-2026-92596 is a high-severity vulnerability in Nodemailer before version 9.1.0. The vulnerability is caused by a quadratic time complexity issue in the addressparser component, which can be exploited by remote attackers to cause a denial of service (DoS) by sending a crafted comma-separated address list in a single email. This can block the Node.js event loop for extended periods, consuming 100% CPU a [truncated]
CVE-2026-92595 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T22:18:30.417Z and has not been modified since then. The NVD entry is currently Received. Defenders responsible for applications using Nodemailer should assess exposure and prioritize upgrading to version 9.1.1 or later. They should also review and restrict usage of the `MailMessage.resolveContent()` API, [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:05.463Z and has not been modified since then. Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. An application passing a custom envelope object with a size property containing CRLF characters to sendMail() can lead to injection [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:05.320Z and has not been modified since then. Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line [truncated]
CVE-2026-82661 executive overview: Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields. This vulnerability allows attackers to inject arbitrary message headers, potentially altering mail client behavior and message semantics. The vulnerability has a CVSS score of 5.3, indicating medium severity. Organizations using Nodemailer versions before 8.0.9 shou [truncated]
PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:03.790Z and has not been modified since then. This vulnerability affects Nodemailer versions before 8.0.9, allowing attackers to read local files or fetch URLs by supplying path or href values in message content fields. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Use [truncated]
CVE-2026-82659 was published on 2026-08-31T09:17:03.633Z and has not been modified since then. The NVD entry is currently Received. This vulnerability exists in nodemailer before version 9.0.1, where the disableFileAccess and disableUrlAccess flags are not applied to the message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery. Evidence is l [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:16:59.387Z and has not been modified since then. The nodemailer package before version 6.9.9 contains a regular expression denial of service vulnerability in email parsing when the attachDataUrls parameter is set or processing embedded file attachments. This could allow attackers to send speci [truncated]
CVE-2026-38728 is a high-severity denial-of-service issue in the Nodemailer smtp-server component before v3.18.3. The supplied record says a remote attacker can trigger the failure through SMTPStream._write in lib/smtp-stream.js. A fix is referenced in the v3.18.3 release, and the NVD record currently shows vulnStatus as Deferred.