Inefficient Algorithmic Complexity in nodemailer - CVE-2026-90776
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the addressparser component when parsing crafted comment-joined email addresses. A remote attacker can send a specially crafted email to cause a denial of service.
The issue is reachable through mailparser processing inbound To, From, or Cc headers.