Inefficient regular expression complexity in nodemailer - CVE-2026-100700
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the addressparser free-text fallback when parsing crafted address header values. A remote attacker can submit a crafted whitespace-free input string that causes quadratic backtracking to cause a denial of service.
The resulting event-loop blockage can stall the entire Node.js process.