Inefficient Algorithmic Complexity in nodemailer - CVE-2026-92596
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the addressparser result accumulator when parsing a crafted comma-separated address list. A remote attacker can provide a crafted address value to cause a denial of service.
The issue occurs on the library's default code path and requires no special application configuration or cooperating receiver.
Affected software
IBM App Connect Enterprise
How to mitigate CVE-2026-92596
IBM App Connect Enterprise - update to 13.0.9.0