---
id: CVE-2026-82853
title: >-
  Nodemailer versions before 8.0.5 contain an SMTP command injection
  vulnerability in the transport name option used in EHLO/HELO commands
summary: >-
  Nodemailer versions before 8.0.5 contain an SMTP command injection
  vulnerability in the transport name option used in EHLO/HELO commands. The
  name parameter is concatenated directly into SMTP commands without sanitizing
  carriage return a…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-93
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:48:28.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82853'
references:
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nodemailer-before-8.0.5-smtp-command-injection-via-crlf
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82853.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-82853'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2526197'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-82853'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82853'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.01031
epssPercentile: 0.62193
ingestedAt: '2026-09-10T15:53:17.039Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - developer_hub
  - enterprise_linux 10
  - self_service_automation_portal 2
---

## Overview

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · no fix planned: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82853.json)
