Interpretation Conflict in nodemailer - CVE-2026-92597
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an interpretation conflict in the Nodemailer address parser when processing a recipient address containing an RFC 5322 comment. A remote attacker can submit a crafted recipient address to disclose sensitive information.
Exploitation requires an application domain check that interprets the address differently from Nodemailer, such as a strict parser whose parse defects are not inspected or a prefix or substring allow-list check.
Affected software
IBM App Connect Enterprise
How to mitigate CVE-2026-92597
IBM App Connect Enterprise - update to 13.0.9.0