Input validation error in nodemailer - CVE-2026-100699
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to alter the integrity of email recipient addressing.
The vulnerability exists due to improper input validation in the Nodemailer address parser when parsing an address with a quoted local-part followed by an RFC 5322 comment and trailing domain text. A remote attacker can supply a crafted recipient address to alter the integrity of email recipient addressing.
The parsed address is propagated into the SMTP envelope without an additional strict recipient-address validation step.