---
id: CVE-2026-82660
title: >-
  Nodemailer before 8.0.9 fails to enforce disableFileAccess and
  disableUrlAccess options during message normalization in jsonTransport
summary: >-
  Nodemailer before 8.0.9 fails to enforce disableFileAccess and
  disableUrlAccess options during message normalization in jsonTransport.
  Attackers can read local files or fetch URLs by supplying path or href values
  in message content field…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
  - CWE-472
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:48:28.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82660'
references:
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nodemailer-jsontransport-bypasses-disablefileaccess-and-disableurlaccess
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82660.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-82660'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2526203'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-82660'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82660'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0026
epssPercentile: 0.15778
ingestedAt: '2026-09-10T15:53:17.039Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - developer_hub
  - enterprise_linux 10
  - self_service_automation_portal 2
---

## Overview

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · no fix planned: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82660.json)
