Uncontrolled Recursion in nodemailer - CVE-2026-100702
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in Nodemailer's recipient address parsing when processing deeply nested recipient arrays. A remote attacker can submit deeply nested recipient arrays to cause a denial of service.
Process termination requires the synchronous exception to be unhandled by the integrating application.