{"id":"GHSA-vm5r-23w9-m8hx","title":"Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)","summary":"Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)","severity":"high","cvss":7.5,"cwe":["CWE-407"],"vendor":"nodemailer","product":"nodemailer","ecosystem":"npm","affected":["nodemailer >= 9.1.0, <= 10.0.4"],"published":"2026-09-13","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:30:02Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vm5r-23w9-m8hx","references":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90776"},{"url":"https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89"},{"url":"https://github.com/nodemailer/nodemailer"},{"url":"https://github.com/nodemailer/nodemailer/blob/v10.0.4/src/addressparser/index.ts#L251"},{"url":"https://github.com/nodemailer/nodemailer/releases/tag/v10.0.5"},{"url":"https://www.vulncheck.com/advisories/nodemailer-9.1.0-through-10.0.4-denial-of-service-via-quadratic-address-parsing"},{"url":"https://github.com/advisories/GHSA-vm5r-23w9-m8hx"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-05T23:36:21.164Z","slug":"GHSA-vm5r-23w9-m8hx","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-prgh-xp8r-p3m5. This link is maintained to preserve external references.\n\n## Original Description\nNodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.\n\n## Affected packages\n\n- `nodemailer >= 9.1.0, <= 10.0.4`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}