Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the… (CVE-2026-100701)
Nodemailer versions 5.0.0 through 10.0.1 have a vulnerability in their DNS caching mechanism where the cache key is only the DNS host, but cache entries also store a caller-specific TLS servername. This causes the wrong SNI value to be sent when multiple TLS transports resolve the same host with different servernames, leading to incorrect certificate validation. An attacker able to prime the cache can cause a victim to connect to the attacker's TLS host and accept a malicious certificate, potentially exposing SMTP credentials. This issue is fixed in Nodemailer version 10.0.2.
AI Analysis
Technical Summary
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache keyed only by DNS host, but each cache entry stores the TLS servername specific to the caller. When two direct TLS/SMTPS transports resolve the same non-IP host with different tls.servername values, the first transport's servername is returned on cache hits, overwriting the second transport's configured value. This causes Nodemailer to send an incorrect SNI value and validate the peer certificate against the wrong identity. In multi-tenant or SNI-routed SMTP gateway environments, an attacker who can prime the DNS cache can cause a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate even with rejectUnauthorized set to true, leading to disclosure of the victim's SMTP credentials. The vulnerability is fixed in version 10.0.2.
Potential Impact
The vulnerability allows an attacker who can prime the DNS cache to cause a victim Nodemailer transport to connect to a malicious TLS host and accept a fraudulent certificate, bypassing TLS certificate validation. This can lead to disclosure of SMTP credentials, compromising email account security. The CVSS score is 5.9 (medium severity), reflecting network attack vector, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
Upgrade Nodemailer to version 10.0.2 or later, where this DNS cache and SNI handling issue is fixed. No other mitigations are indicated or required once the update is applied.
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the… (CVE-2026-100701)
Description
Nodemailer versions 5.0.0 through 10.0.1 have a vulnerability in their DNS caching mechanism where the cache key is only the DNS host, but cache entries also store a caller-specific TLS servername. This causes the wrong SNI value to be sent when multiple TLS transports resolve the same host with different servernames, leading to incorrect certificate validation. An attacker able to prime the cache can cause a victim to connect to the attacker's TLS host and accept a malicious certificate, potentially exposing SMTP credentials. This issue is fixed in Nodemailer version 10.0.2.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache keyed only by DNS host, but each cache entry stores the TLS servername specific to the caller. When two direct TLS/SMTPS transports resolve the same non-IP host with different tls.servername values, the first transport's servername is returned on cache hits, overwriting the second transport's configured value. This causes Nodemailer to send an incorrect SNI value and validate the peer certificate against the wrong identity. In multi-tenant or SNI-routed SMTP gateway environments, an attacker who can prime the DNS cache can cause a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate even with rejectUnauthorized set to true, leading to disclosure of the victim's SMTP credentials. The vulnerability is fixed in version 10.0.2.
Potential Impact
The vulnerability allows an attacker who can prime the DNS cache to cause a victim Nodemailer transport to connect to a malicious TLS host and accept a fraudulent certificate, bypassing TLS certificate validation. This can lead to disclosure of SMTP credentials, compromising email account security. The CVSS score is 5.9 (medium severity), reflecting network attack vector, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
Upgrade Nodemailer to version 10.0.2 or later, where this DNS cache and SNI handling issue is fixed. No other mitigations are indicated or required once the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2mg4-38wg-2h6f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100701"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab89bdbf7a7c54106942028
Added to database: 09/27/2026, 04:30:19 UTC
Last enriched: 09/27/2026, 04:41:46 UTC
Last updated: 09/28/2026, 01:47:40 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.