Vulnerability DatabaseCVE-2026-100701

CVE-2026-100701: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100701 is a TLS servername cache confusion vulnerability in Nodemailer that enables cross-tenant SMTP credential disclosure. Affecting versions 5.0.0 through 10.0.1 of the nodemailer npm package, the flaw stems from a process-global DNS cache that is keyed only by hostname but stores caller-specific TLS servername values, causing subsequent transports to inherit a stale SNI identity from a prior transport. The vulnerability was published on September 26, 2026, with a fix available in version 10.0.2. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation), with secondary weaknesses CWE-923 (Improper Restriction of Communication Channel) and CWE-522 (Insufficiently Protected Credentials). In src/shared/index.ts, the module-global dnsCache Map is keyed solely by DNS hostname, yet each cached entry stores both resolved addresses and the caller-specific tls.servername. When a second transport resolves the same host within the 5-minute default TTL, resolveHostname() returns the cached entry — including the first transport's servername — and _resolveAndConnect() in src/smtp-connection/index.ts overwrites the current connection's opts.servername with this stale value before calling tls.connect(). The vulnerable cache implementation was introduced in commit 6859b5dd96c8d9f0070a3169a877181b71df4a3b on 2018-12-28 and is present from v5.0.0 through v10.0.1. A public proof-of-concept is included in the GitHub Security Advisory, demonstrating that a victim transport configured with rejectUnauthorized: true and a distinct tls.servername will nonetheless connect to and authenticate against an attacker-controlled TLS virtual host (GitHub Advisory GHSA-6vj9-mwq6-2f5v).

Impact

Successful exploitation allows an attacker to intercept SMTP credentials (username and password) from a victim transport operating in the same Node.js process. Because the victim's connection is directed to the attacker's TLS virtual host — and the attacker's certificate is accepted even with strict validation enabled — the victim's AUTH credentials are transmitted in plaintext to the attacker. Secondary impacts include the ability to send email as the victim, read or modify mail account state if the provider reuses SMTP credentials, and cross-tenant availability disruption where SNI mismatch causes connection failures for other tenants. The vulnerability is scoped to multi-tenant services or SNI-routed SMTP gateways where multiple transports share a DNS hostname within a single process (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).

Exploitability

A public proof-of-concept is included in the official GitHub Security Advisory (GHSA-6vj9-mwq6-2f5v), demonstrating the full attack path with Node.js 20 and a local TLS server — no external SMTP server or network access is required to reproduce. There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0, indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an attacker to hold low-level privileges (e.g., the ability to create or exercise a Nodemailer transport in the same process) and depends on specific deployment conditions: shared DNS host, distinct tls.servername values, and an SNI-aware SMTP endpoint (GitHub Advisory GHSA-6vj9-mwq6-2f5v, GitHub Advisory GHSA-2mg4-38wg-2h6f).

Exploitation steps

  1. Identify a vulnerable deployment: Locate a multi-tenant Node.js application using Nodemailer 5.0.0–10.0.1 where multiple tenants can configure SMTP transports sharing the same DNS hostname (e.g., an SNI-routed SMTP gateway) within a single process.
  2. Obtain low-privilege access: Acquire the ability to create or trigger a Nodemailer transport in the target process — for example, by registering as a tenant on a shared email platform.
  3. Prime the DNS cache: Create a direct SMTPS transport (secure: true) targeting the shared DNS hostname with tls.servername set to the attacker's own TLS virtual host name (e.g., attacker.example.com). Initiate a connection to populate the process-global dnsCache with the attacker's servername.
  4. Wait for victim transport: Within the 5-minute cache TTL, wait for a victim tenant's transport — configured with a different tls.servername (e.g., victim.example.com) and the same DNS host — to initiate a connection.
  5. Cache confusion triggers wrong SNI: When the victim transport calls resolveHostname(), it receives the cached entry containing the attacker's servername. The _resolveAndConnect() function overwrites opts.servername with the attacker's value before calling tls.connect().
  6. Attacker's TLS virtual host is selected: The SNI-aware gateway routes the victim's connection to the attacker's TLS endpoint; the attacker's certificate is presented and accepted by the victim transport even with rejectUnauthorized: true.
  7. Capture SMTP credentials: The victim transport proceeds through SMTP AUTH, transmitting the victim's username and password (e.g., via AUTH PLAIN) to the attacker-controlled server, which logs the credentials (GitHub Advisory GHSA-6vj9-mwq6-2f5v).

Indicators of compromise

  • Network: Unexpected TLS connections from a Nodemailer-based service to an unrecognized or attacker-controlled SMTP endpoint on port 465 (SMTPS); SNI values in TLS ClientHello packets that do not match the intended recipient domain for a given tenant.
  • Logs: SMTP AUTH commands (e.g., AUTH PLAIN) observed in server logs for connections where the SNI hostname does not match the tenant's configured tls.servername; successful TLS handshakes to unexpected virtual hosts despite rejectUnauthorized: true being set.
  • Application Behavior: Multiple Nodemailer transports in the same process connecting to the same DNS host but receiving unexpected certificate CN/SAN values without raising errors; tenant A's servername appearing in connection metadata for tenant B's transport.
  • Process: Node.js process establishing outbound TLS connections where the negotiated server certificate's Subject Alternative Name does not match the application-configured tls.servername for that transport (GitHub Advisory GHSA-6vj9-mwq6-2f5v).

Mitigation and workarounds

Upgrade Nodemailer to version 10.0.2 or later, which fixes the DNS cache to exclude servername from cached entries and derives the TLS identity from the current request on every code path (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla). As a short-term workaround where upgrading is not immediately possible, avoid sharing a DNS hostname across transports with different tls.servername values in the same process, or use IP addresses instead of hostnames for SMTP hosts (IP-addressed hosts bypass the DNS cache path). Additionally, ensure each tenant's transport uses a unique, non-shared DNS hostname to prevent cache key collisions.

Community reactions

The vulnerability was reported by security researcher ry2811 and published via the official Nodemailer GitHub Security Advisory (GHSA-6vj9-mwq6-2f5v) on September 10, 2026, with the CVE assigned and publicly disclosed on September 26, 2026. Red Hat opened a tracking bug (Bugzilla #2541849) and classified the severity as medium. No significant broader media coverage or notable social media commentary has been identified at this time (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

node-nodemailer

Affected

sid

node-nodemailer: 10.0.10+~8.0.1-1

Fixed

trixie

node-nodemailer

Affected

RHEL / CentOS

Affected

RHEL 10

grafana.src

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100700HIGH8.7
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100699MEDIUM6.9
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-100694MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoNoSep 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management