
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100700 is a Regular Expression Denial of Service (ReDoS) vulnerability in the nodemailer npm package affecting all versions before 10.0.6. The flaw resides in the addressparser component's free-text fallback regex pattern (/\s*\b[^@\s]+@[^\s]+\b\s*/), which exhibits quadratic backtracking behavior when processing crafted email header values containing long whitespace-free runs. Attackers can supply malicious input to block the Node.js event loop for tens of seconds, causing service unavailability. The vulnerability was published on September 26, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory GHSA-v53p-9fqp-m79j, GitHub Advisory GHSA-c7vw-frhj-6h9j).
The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and CWE-407 (Inefficient Algorithmic Complexity). When addressparser in src/addressparser/index.ts fails to find an address via its strict parser, it falls back to the regex /\s*\b[^@\s]+@[^\s]+\b\s*/ applied as a search. The [^@\s]+ quantifier causes the engine to retry from every character offset, rescanning the run to the next @ each time — resulting in O(n²) backtracking. Four input shapes trigger worst-case behavior: a run with no @, a run where @ has nothing after it, a run where @ has nothing before it, and a run with a valid address placed after a long whitespace-free prefix. A public PoC is included in the advisory: addressparser(' >' + '>[x][x]'.repeat(40000)) (273 KB) blocks the event loop for approximately 43 seconds on version 10.0.5 (GitHub Advisory GHSA-v53p-9fqp-m79j).
Successful exploitation causes a complete availability denial of the affected Node.js process, as Node.js is single-threaded and the blocked event loop stalls all request handling for the duration of the regex evaluation. The vulnerability is reachable without authentication wherever inbound email header values are passed to the parser — notably via mailparser — and also from application input wherever user-supplied strings are used as message addresses (e.g., to, from, cc fields during MIME composition). There is no confidentiality or integrity impact; the sole consequence is service unavailability (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).
A PoC is publicly available within the official security advisory, demonstrating that a 273 KB crafted string can block the event loop for ~43 seconds, making exploitation straightforward and low-cost compared to the related predecessor vulnerability GHSA-prgh-xp8r-p3m5 (which required ~1.5 MB for ~10 seconds). No authentication or user interaction is required. As of the publication date, there is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory GHSA-v53p-9fqp-m79j, GitHub Advisory GHSA-c7vw-frhj-6h9j).
addressparser — either via inbound email header parsing (e.g., through mailparser) or via user-supplied to/from/cc fields in email composition.' >' + '>[x][x]'.repeat(40000) (~273 KB), which contains no valid email address and forces the fallback regex to scan every offset.To:, From:, Cc:) via the application's exposed interface — an API endpoint, web form, or SMTP input — that routes the value to addressparser.src/addressparser/index.ts begins quadratic backtracking, blocking the Node.js event loop for tens of seconds (~43s for the 273 KB payload on version 10.0.5).perf_hooks or APM tools) showing multi-second delays.Upgrade nodemailer to version 10.0.6 or later, which replaces the vulnerable regex search with a single linear pass that finds the one valid match offset using a sticky regex, eliminating quadratic backtracking while preserving identical match results (verified against 3.4 million random strings). No configuration-based workaround is documented; upgrading is the only recommended remediation. Applications using mailparser or any library that internally calls addressparser should also verify their transitive dependency on nodemailer is updated (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).
The vulnerability was discovered internally by the nodemailer maintainer (andris9) while validating a related report (GHSA-prgh-xp8r-p3m5) and was not reported externally. Red Hat's Product Security team tracked it via Bugzilla with high priority and severity, with 21 users CC'd, indicating broad internal concern across Red Hat product lines. No significant public social media commentary or independent researcher analysis beyond the official advisory has been identified at this time (GitHub Advisory GHSA-v53p-9fqp-m79j, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."