Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause… (CVE-2026-92596)
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
AI Analysis
Technical Summary
Nodemailer before version 9.1.0 contains a denial of service vulnerability due to a quadratic time complexity issue in its addressparser component. An attacker can exploit this by supplying a specially crafted comma-separated list of email addresses, causing the Node.js event loop to be blocked for extended periods. This results in high CPU usage and freezing of the process, effectively causing a denial of service.
Potential Impact
The vulnerability allows remote attackers to cause a denial of service by sending a single email with a large number of addresses. This leads to 100% CPU consumption and freezing of the Node.js event loop, disrupting normal operation of applications using vulnerable Nodemailer versions.
Mitigation Recommendations
A fix is available in Nodemailer version 9.1.0. Users should upgrade to version 9.1.0 or later to remediate this vulnerability. No other mitigation guidance is provided.
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause… (CVE-2026-92596)
Description
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Nodemailer before version 9.1.0 contains a denial of service vulnerability due to a quadratic time complexity issue in its addressparser component. An attacker can exploit this by supplying a specially crafted comma-separated list of email addresses, causing the Node.js event loop to be blocked for extended periods. This results in high CPU usage and freezing of the process, effectively causing a denial of service.
Potential Impact
The vulnerability allows remote attackers to cause a denial of service by sending a single email with a large number of addresses. This leads to 100% CPU consumption and freezing of the Node.js event loop, disrupting normal operation of applications using vulnerable Nodemailer versions.
Mitigation Recommendations
A fix is available in Nodemailer version 9.1.0. Users should upgrade to version 9.1.0 or later to remediate this vulnerability. No other mitigation guidance is provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v554-hhrr-96v5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92596"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aab494255bf5e2cf59903e8
Added to database: 09/17/2026, 01:58:26 UTC
Last enriched: 09/17/2026, 02:01:37 UTC
Last updated: 09/17/2026, 04:21:29 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.