
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100702 is a Denial of Service vulnerability in Nodemailer caused by improper handling of deeply nested arrays in recipient fields (to, cc, bcc). Attackers can supply a crafted deeply nested JSON recipient array that triggers recursive Array.prototype.toString() conversion, exhausting the V8 call stack and terminating the Node.js process. All Nodemailer versions before 10.0.2 are affected, with confirmed vulnerable versions including 2.7.2, 3.0.0, 7.0.11, 9.1.1, and 10.0.1. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory GHSA-8vvx-rff5-p5rq, Red Hat Bugzilla). The vulnerability was published on September 26, 2026, and is distinct from the previously patched CVE-2025-14874 (GHSA-rcmh-qjqh-p98v), which addressed a different recursive parsing path (GitHub Advisory GHSA-8vvx-rff5-p5rq).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-674 (Uncontrolled Recursion). The public MimeNodeAddressInput TypeScript type is recursively defined, permitting arbitrarily nested arrays as recipient values. The _parseAddresses() method in src/mime-node/index.ts only flattens the outermost array via [].concat(addresses), leaving inner nested arrays intact; these are then passed to addressparser(), whose Tokenizer constructor coerces the input with .toString(). When the input is a deeply nested array, this triggers native Array.prototype.toString() → Array.join() recursion until V8 raises RangeError: Maximum call stack size exceeded. Critically, Nodemailer's maxRecipients guard is evaluated only after getEnvelope() is called — which is where the exception occurs — so it cannot prevent the crash. A proof-of-concept payload of approximately 10 KB (one email address wrapped in 5,000 nested arrays) reliably reproduces the crash (GitHub Advisory GHSA-8vvx-rff5-p5rq).
Successful exploitation causes an unhandled RangeError that terminates the Node.js worker or server process, resulting in a complete availability loss for the affected service. There is no confidentiality or integrity impact — the vulnerability is purely a Denial of Service. Affected integrations include email-sending HTTP APIs accepting structured recipient values, notification workers consuming JSON from queues, multi-tenant applications allowing user-configured recipients, and template/automation systems forwarding parsed recipient data to sendMail(). Repeated malicious inputs can keep process managers in a restart loop, sustaining service unavailability (GitHub Advisory GHSA-8vvx-rff5-p5rq).
A public proof-of-concept is included in the GitHub Security Advisory (GHSA-8vvx-rff5-p5rq) and requires no SMTP server, authentication, or network connection to demonstrate — only a crafted JSON payload passed to sendMail(). No in-the-wild exploitation has been reported as of the disclosure date, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is 0.0, reflecting low current exploitation probability (GitHub Advisory GHSA-8vvx-rff5-p5rq, GitHub Advisory GHSA-5hcf-56h7-4fvx). Attack complexity is rated High due to the prerequisite that the application must accept and preserve nested array structures from attacker-controlled input before passing them to Nodemailer.
to, cc, bcc) and pass them as structured JSON arrays to Nodemailer without flattening or depth-limiting the input.'['.repeat(5000) + '"victim@example.test"' + ']'.repeat(5000). This produces a ~10 KB JSON string.JSON.parse() (as would occur in an HTTP API or queue worker) and submit it as the to, cc, or bcc field in a request to the target application.nodemailer.sendMail(). Inside _parseAddresses(), the nested array bypasses the outer concat() flattening and is passed to addressparser(), whose Tokenizer calls .toString() on the array, triggering unbounded Array.join/Array.toString recursion.RangeError: Maximum call stack size exceeded. If the application does not wrap the full sendMail() invocation in exception handling, the Node.js process terminates. Repeated requests sustain a denial-of-service condition (GitHub Advisory GHSA-8vvx-rff5-p5rq).RangeError: Maximum call stack size exceeded with a stack trace showing repeated Array.join and Array.toString frames originating from Nodemailer's addressparser or mime-node modules.sendMail() invocations with deeply nested recipient values in request logs or queue job records; unusually large or deeply structured JSON payloads in the to, cc, or bcc fields.Upgrade Nodemailer to version 10.0.2 or later, which addresses the vulnerability by iteratively flattening nested recipient arrays before passing values to addressparser() (GitHub Advisory GHSA-8vvx-rff5-p5rq). As an interim workaround, applications should validate and reject recipient inputs that contain nested arrays or exceed a defined nesting depth before calling sendMail(). Additionally, wrapping the complete sendMail() invocation in a try/catch block (or handling rejected Promises) will prevent process termination, though it does not eliminate the underlying vulnerability. Applications that accept only flat strings or flat arrays of recipient addresses as input are not exposed to this attack path.
The vulnerability was reported by security researcher ry2811 and published by Nodemailer maintainer andris9 via GitHub Security Advisory GHSA-8vvx-rff5-p5rq on September 10, 2026, with CVE assignment and broader disclosure on September 26, 2026 (GitHub Advisory GHSA-8vvx-rff5-p5rq). Red Hat tracked the issue via Bugzilla (Bug 2541816) and assigned it medium priority/severity for their product lines (Red Hat Bugzilla). No significant broader media coverage or notable social media discussion has been identified beyond standard CVE aggregator publications.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."