Inefficient Algorithmic Complexity in nodemailer - CVE-2026-92596

 

Inefficient Algorithmic Complexity in nodemailer - CVE-2026-92596

Published: September 30, 2026


Vulnerability identifier: #VU153011
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92596
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in the addressparser result accumulator when parsing a crafted comma-separated address list. A remote attacker can provide a crafted address value to cause a denial of service.

The issue occurs on the library's default code path and requires no special application configuration or cooperating receiver.


Affected software

nodemailer
IBM App Connect Enterprise

How to mitigate CVE-2026-92596

Install security update from vendor's website.

nodemailer - update to 9.1.0
IBM App Connect Enterprise - update to 13.0.9.0

External References

Related Security Bulletins