Vulnerability DatabaseCVE-2026-100702

CVE-2026-100702: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100702 is a Denial of Service vulnerability in Nodemailer caused by improper handling of deeply nested arrays in recipient fields (to, cc, bcc). Attackers can supply a crafted deeply nested JSON recipient array that triggers recursive Array.prototype.toString() conversion, exhausting the V8 call stack and terminating the Node.js process. All Nodemailer versions before 10.0.2 are affected, with confirmed vulnerable versions including 2.7.2, 3.0.0, 7.0.11, 9.1.1, and 10.0.1. It carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory GHSA-8vvx-rff5-p5rq, Red Hat Bugzilla). The vulnerability was published on September 26, 2026, and is distinct from the previously patched CVE-2025-14874 (GHSA-rcmh-qjqh-p98v), which addressed a different recursive parsing path (GitHub Advisory GHSA-8vvx-rff5-p5rq).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-674 (Uncontrolled Recursion). The public MimeNodeAddressInput TypeScript type is recursively defined, permitting arbitrarily nested arrays as recipient values. The _parseAddresses() method in src/mime-node/index.ts only flattens the outermost array via [].concat(addresses), leaving inner nested arrays intact; these are then passed to addressparser(), whose Tokenizer constructor coerces the input with .toString(). When the input is a deeply nested array, this triggers native Array.prototype.toString() → Array.join() recursion until V8 raises RangeError: Maximum call stack size exceeded. Critically, Nodemailer's maxRecipients guard is evaluated only after getEnvelope() is called — which is where the exception occurs — so it cannot prevent the crash. A proof-of-concept payload of approximately 10 KB (one email address wrapped in 5,000 nested arrays) reliably reproduces the crash (GitHub Advisory GHSA-8vvx-rff5-p5rq).

Impact

Successful exploitation causes an unhandled RangeError that terminates the Node.js worker or server process, resulting in a complete availability loss for the affected service. There is no confidentiality or integrity impact — the vulnerability is purely a Denial of Service. Affected integrations include email-sending HTTP APIs accepting structured recipient values, notification workers consuming JSON from queues, multi-tenant applications allowing user-configured recipients, and template/automation systems forwarding parsed recipient data to sendMail(). Repeated malicious inputs can keep process managers in a restart loop, sustaining service unavailability (GitHub Advisory GHSA-8vvx-rff5-p5rq).

Exploitability

A public proof-of-concept is included in the GitHub Security Advisory (GHSA-8vvx-rff5-p5rq) and requires no SMTP server, authentication, or network connection to demonstrate — only a crafted JSON payload passed to sendMail(). No in-the-wild exploitation has been reported as of the disclosure date, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is 0.0, reflecting low current exploitation probability (GitHub Advisory GHSA-8vvx-rff5-p5rq, GitHub Advisory GHSA-5hcf-56h7-4fvx). Attack complexity is rated High due to the prerequisite that the application must accept and preserve nested array structures from attacker-controlled input before passing them to Nodemailer.

Exploitation steps

  1. Reconnaissance: Identify applications that accept attacker-controlled recipient fields (e.g., to, cc, bcc) and pass them as structured JSON arrays to Nodemailer without flattening or depth-limiting the input.
  2. Craft the payload: Construct a deeply nested JSON array containing a single valid email address, e.g., '['.repeat(5000) + '"victim@example.test"' + ']'.repeat(5000). This produces a ~10 KB JSON string.
  3. Parse and submit: Parse the JSON string with JSON.parse() (as would occur in an HTTP API or queue worker) and submit it as the to, cc, or bcc field in a request to the target application.
  4. Trigger the crash: The application passes the nested array to nodemailer.sendMail(). Inside _parseAddresses(), the nested array bypasses the outer concat() flattening and is passed to addressparser(), whose Tokenizer calls .toString() on the array, triggering unbounded Array.join/Array.toString recursion.
  5. Process termination: V8 raises RangeError: Maximum call stack size exceeded. If the application does not wrap the full sendMail() invocation in exception handling, the Node.js process terminates. Repeated requests sustain a denial-of-service condition (GitHub Advisory GHSA-8vvx-rff5-p5rq).

Indicators of compromise

  • Logs: Node.js process crash logs containing RangeError: Maximum call stack size exceeded with a stack trace showing repeated Array.join and Array.toString frames originating from Nodemailer's addressparser or mime-node modules.
  • Process: Unexpected or repeated Node.js process restarts by a process manager (e.g., PM2, systemd) for the mail-sending service, particularly correlated with inbound API or queue activity.
  • Application Logs: Repeated failed sendMail() invocations with deeply nested recipient values in request logs or queue job records; unusually large or deeply structured JSON payloads in the to, cc, or bcc fields.
  • Network: High-frequency requests to email-sending API endpoints from a single source IP, especially if each request results in a process restart (GitHub Advisory GHSA-8vvx-rff5-p5rq).

Mitigation and workarounds

Upgrade Nodemailer to version 10.0.2 or later, which addresses the vulnerability by iteratively flattening nested recipient arrays before passing values to addressparser() (GitHub Advisory GHSA-8vvx-rff5-p5rq). As an interim workaround, applications should validate and reject recipient inputs that contain nested arrays or exceed a defined nesting depth before calling sendMail(). Additionally, wrapping the complete sendMail() invocation in a try/catch block (or handling rejected Promises) will prevent process termination, though it does not eliminate the underlying vulnerability. Applications that accept only flat strings or flat arrays of recipient addresses as input are not exposed to this attack path.

Community reactions

The vulnerability was reported by security researcher ry2811 and published by Nodemailer maintainer andris9 via GitHub Security Advisory GHSA-8vvx-rff5-p5rq on September 10, 2026, with CVE assignment and broader disclosure on September 26, 2026 (GitHub Advisory GHSA-8vvx-rff5-p5rq). Red Hat tracked the issue via Bugzilla (Bug 2541816) and assigned it medium priority/severity for their product lines (Red Hat Bugzilla). No significant broader media coverage or notable social media discussion has been identified beyond standard CVE aggregator publications.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

node-nodemailer

Affected

sid

node-nodemailer: 10.0.10+~8.0.1-1

Fixed

trixie

node-nodemailer

Affected

RHEL / CentOS

Affected

RHEL 10

grafana.src

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100700HIGH8.7
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100699MEDIUM6.9
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-100694MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoNoSep 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management