
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100701 is a TLS servername cache confusion vulnerability in Nodemailer that enables cross-tenant SMTP credential disclosure. Affecting versions 5.0.0 through 10.0.1 of the nodemailer npm package, the flaw stems from a process-global DNS cache that is keyed only by hostname but stores caller-specific TLS servername values, causing subsequent transports to inherit a stale SNI identity from a prior transport. The vulnerability was published on September 26, 2026, with a fix available in version 10.0.2. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).
The root cause is classified as CWE-295 (Improper Certificate Validation), with secondary weaknesses CWE-923 (Improper Restriction of Communication Channel) and CWE-522 (Insufficiently Protected Credentials). In src/shared/index.ts, the module-global dnsCache Map is keyed solely by DNS hostname, yet each cached entry stores both resolved addresses and the caller-specific tls.servername. When a second transport resolves the same host within the 5-minute default TTL, resolveHostname() returns the cached entry — including the first transport's servername — and _resolveAndConnect() in src/smtp-connection/index.ts overwrites the current connection's opts.servername with this stale value before calling tls.connect(). The vulnerable cache implementation was introduced in commit 6859b5dd96c8d9f0070a3169a877181b71df4a3b on 2018-12-28 and is present from v5.0.0 through v10.0.1. A public proof-of-concept is included in the GitHub Security Advisory, demonstrating that a victim transport configured with rejectUnauthorized: true and a distinct tls.servername will nonetheless connect to and authenticate against an attacker-controlled TLS virtual host (GitHub Advisory GHSA-6vj9-mwq6-2f5v).
Successful exploitation allows an attacker to intercept SMTP credentials (username and password) from a victim transport operating in the same Node.js process. Because the victim's connection is directed to the attacker's TLS virtual host — and the attacker's certificate is accepted even with strict validation enabled — the victim's AUTH credentials are transmitted in plaintext to the attacker. Secondary impacts include the ability to send email as the victim, read or modify mail account state if the provider reuses SMTP credentials, and cross-tenant availability disruption where SNI mismatch causes connection failures for other tenants. The vulnerability is scoped to multi-tenant services or SNI-routed SMTP gateways where multiple transports share a DNS hostname within a single process (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).
A public proof-of-concept is included in the official GitHub Security Advisory (GHSA-6vj9-mwq6-2f5v), demonstrating the full attack path with Node.js 20 and a local TLS server — no external SMTP server or network access is required to reproduce. There is no evidence of in-the-wild exploitation at this time, and the EPSS score is 0.0, indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an attacker to hold low-level privileges (e.g., the ability to create or exercise a Nodemailer transport in the same process) and depends on specific deployment conditions: shared DNS host, distinct tls.servername values, and an SNI-aware SMTP endpoint (GitHub Advisory GHSA-6vj9-mwq6-2f5v, GitHub Advisory GHSA-2mg4-38wg-2h6f).
secure: true) targeting the shared DNS hostname with tls.servername set to the attacker's own TLS virtual host name (e.g., attacker.example.com). Initiate a connection to populate the process-global dnsCache with the attacker's servername.tls.servername (e.g., victim.example.com) and the same DNS host — to initiate a connection.resolveHostname(), it receives the cached entry containing the attacker's servername. The _resolveAndConnect() function overwrites opts.servername with the attacker's value before calling tls.connect().rejectUnauthorized: true.AUTH PLAIN) observed in server logs for connections where the SNI hostname does not match the tenant's configured tls.servername; successful TLS handshakes to unexpected virtual hosts despite rejectUnauthorized: true being set.servername appearing in connection metadata for tenant B's transport.tls.servername for that transport (GitHub Advisory GHSA-6vj9-mwq6-2f5v).Upgrade Nodemailer to version 10.0.2 or later, which fixes the DNS cache to exclude servername from cached entries and derives the TLS identity from the current request on every code path (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla). As a short-term workaround where upgrading is not immediately possible, avoid sharing a DNS hostname across transports with different tls.servername values in the same process, or use IP addresses instead of hostnames for SMTP hosts (IP-addressed hosts bypass the DNS cache path). Additionally, ensure each tenant's transport uses a unique, non-shared DNS hostname to prevent cache key collisions.
The vulnerability was reported by security researcher ry2811 and published via the official Nodemailer GitHub Security Advisory (GHSA-6vj9-mwq6-2f5v) on September 10, 2026, with the CVE assigned and publicly disclosed on September 26, 2026. Red Hat opened a tracking bug (Bugzilla #2541849) and classified the severity as medium. No significant broader media coverage or notable social media commentary has been identified at this time (GitHub Advisory GHSA-6vj9-mwq6-2f5v, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."