Vulnerability DatabaseCVE-2026-100700

CVE-2026-100700: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100700 is a Regular Expression Denial of Service (ReDoS) vulnerability in the nodemailer npm package affecting all versions before 10.0.6. The flaw resides in the addressparser component's free-text fallback regex pattern (/\s*\b[^@\s]+@[^\s]+\b\s*/), which exhibits quadratic backtracking behavior when processing crafted email header values containing long whitespace-free runs. Attackers can supply malicious input to block the Node.js event loop for tens of seconds, causing service unavailability. The vulnerability was published on September 26, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory GHSA-v53p-9fqp-m79j, GitHub Advisory GHSA-c7vw-frhj-6h9j).

Technical details

The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and CWE-407 (Inefficient Algorithmic Complexity). When addressparser in src/addressparser/index.ts fails to find an address via its strict parser, it falls back to the regex /\s*\b[^@\s]+@[^\s]+\b\s*/ applied as a search. The [^@\s]+ quantifier causes the engine to retry from every character offset, rescanning the run to the next @ each time — resulting in O(n²) backtracking. Four input shapes trigger worst-case behavior: a run with no @, a run where @ has nothing after it, a run where @ has nothing before it, and a run with a valid address placed after a long whitespace-free prefix. A public PoC is included in the advisory: addressparser(' >' + '>[x][x]'.repeat(40000)) (273 KB) blocks the event loop for approximately 43 seconds on version 10.0.5 (GitHub Advisory GHSA-v53p-9fqp-m79j).

Impact

Successful exploitation causes a complete availability denial of the affected Node.js process, as Node.js is single-threaded and the blocked event loop stalls all request handling for the duration of the regex evaluation. The vulnerability is reachable without authentication wherever inbound email header values are passed to the parser — notably via mailparser — and also from application input wherever user-supplied strings are used as message addresses (e.g., to, from, cc fields during MIME composition). There is no confidentiality or integrity impact; the sole consequence is service unavailability (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).

Exploitability

A PoC is publicly available within the official security advisory, demonstrating that a 273 KB crafted string can block the event loop for ~43 seconds, making exploitation straightforward and low-cost compared to the related predecessor vulnerability GHSA-prgh-xp8r-p3m5 (which required ~1.5 MB for ~10 seconds). No authentication or user interaction is required. As of the publication date, there is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory GHSA-v53p-9fqp-m79j, GitHub Advisory GHSA-c7vw-frhj-6h9j).

Exploitation steps

  1. Identify target: Locate a Node.js application that uses nodemailer ≤ 10.0.5 and exposes an endpoint that passes user-controlled input to addressparser — either via inbound email header parsing (e.g., through mailparser) or via user-supplied to/from/cc fields in email composition.
  2. Craft malicious payload: Construct a string containing a long whitespace-free run that triggers worst-case regex backtracking. Example PoC from the advisory: ' >' + '>[x][x]'.repeat(40000) (~273 KB), which contains no valid email address and forces the fallback regex to scan every offset.
  3. Deliver payload: Submit the crafted string as an email header value (e.g., To:, From:, Cc:) via the application's exposed interface — an API endpoint, web form, or SMTP input — that routes the value to addressparser.
  4. Trigger event loop block: The vulnerable regex in src/addressparser/index.ts begins quadratic backtracking, blocking the Node.js event loop for tens of seconds (~43s for the 273 KB payload on version 10.0.5).
  5. Achieve denial of service: During the block, the entire Node.js process is unresponsive, causing service unavailability for all concurrent users. Repeated submissions can sustain the outage indefinitely (GitHub Advisory GHSA-v53p-9fqp-m79j).

Indicators of compromise

  • Logs: Node.js application logs showing unusually long request processing times (tens of seconds) for endpoints that handle email address input; timeout errors or health check failures coinciding with specific inbound requests.
  • Process: Node.js process CPU usage spiking to 100% on a single core for extended periods (10–60+ seconds) without corresponding I/O activity; event loop lag metrics (e.g., from perf_hooks or APM tools) showing multi-second delays.
  • Network: Inbound HTTP or SMTP requests containing abnormally large header values (hundreds of KB) with long whitespace-free character sequences and no valid email address structure; repeated requests of this shape from the same source IP.
  • Application Metrics: Sudden drops in request throughput or response rate correlated with receipt of large email-header-containing payloads; increased error rates on email-processing endpoints (GitHub Advisory GHSA-v53p-9fqp-m79j).

Mitigation and workarounds

Upgrade nodemailer to version 10.0.6 or later, which replaces the vulnerable regex search with a single linear pass that finds the one valid match offset using a sticky regex, eliminating quadratic backtracking while preserving identical match results (verified against 3.4 million random strings). No configuration-based workaround is documented; upgrading is the only recommended remediation. Applications using mailparser or any library that internally calls addressparser should also verify their transitive dependency on nodemailer is updated (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).

Community reactions

The vulnerability was discovered internally by the nodemailer maintainer (andris9) while validating a related report (GHSA-prgh-xp8r-p3m5) and was not reported externally. Red Hat's Product Security team tracked it via Bugzilla with high priority and severity, with 21 users CC'd, indicating broad internal concern across Red Hat product lines. No significant public social media commentary or independent researcher analysis beyond the official advisory has been identified at this time (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

node-nodemailer

Affected

sid

node-nodemailer: 10.0.10+~8.0.1-1

Fixed

trixie

node-nodemailer

Affected

RHEL / CentOS

Affected

RHEL 10

Not Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100700HIGH8.7
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100699MEDIUM6.9
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-100694MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoNoSep 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management