Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a… (CVE-2026-92598)
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
AI Analysis
Technical Summary
The vulnerability in Nodemailer prior to version 9.1.0 involves improper handling of internationalized domain names (IDNs). Specifically, the software fails to apply UTS-46 normalization during encoding, leading to discrepancies in the computed Punycode A-label compared to standards-compliant parsers. This inconsistency allows attackers to create recipient addresses with invisible or compatibility-mapped characters that evade domain allow-list filters but ultimately route emails to attacker-controlled domains. This can undermine domain-based security controls relying on allow-lists.
Potential Impact
This vulnerability can lead to bypassing domain allow-list checks in email sending workflows, potentially causing emails intended for trusted domains to be redirected to attacker-controlled domains. The impact includes confidentiality risks due to misdirected emails. The CVSS score of 6.5 (high severity) reflects a network attack vector with high confidentiality impact but low integrity and no availability impact. Exploitation requires high attack complexity and no privileges or user interaction.
Mitigation Recommendations
A fix is available in Nodemailer version 9.1.0 and later, which correctly applies UTS-46 normalization for international domain names. Users should upgrade to version 9.1.0 or newer to remediate this issue. Since this is a software library, patching the dependency in affected applications is necessary. No vendor advisory content was provided, so patch status is inferred from the version information in the description.
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a… (CVE-2026-92598)
Description
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Nodemailer prior to version 9.1.0 involves improper handling of internationalized domain names (IDNs). Specifically, the software fails to apply UTS-46 normalization during encoding, leading to discrepancies in the computed Punycode A-label compared to standards-compliant parsers. This inconsistency allows attackers to create recipient addresses with invisible or compatibility-mapped characters that evade domain allow-list filters but ultimately route emails to attacker-controlled domains. This can undermine domain-based security controls relying on allow-lists.
Potential Impact
This vulnerability can lead to bypassing domain allow-list checks in email sending workflows, potentially causing emails intended for trusted domains to be redirected to attacker-controlled domains. The impact includes confidentiality risks due to misdirected emails. The CVSS score of 6.5 (high severity) reflects a network attack vector with high confidentiality impact but low integrity and no availability impact. Exploitation requires high attack complexity and no privileges or user interaction.
Mitigation Recommendations
A fix is available in Nodemailer version 9.1.0 and later, which correctly applies UTS-46 normalization for international domain names. Users should upgrade to version 9.1.0 or newer to remediate this issue. Since this is a software library, patching the dependency in affected applications is necessary. No vendor advisory content was provided, so patch status is inferred from the version information in the description.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r7q5-h7cx-p54x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92598"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aab494255bf5e2cf59903e9
Added to database: 09/17/2026, 01:58:26 UTC
Last enriched: 09/17/2026, 02:01:41 UTC
Last updated: 09/17/2026, 02:31:47 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.