GHSA-frj6-5rhh-vwfwHigh· 6.5▾ TwilightDuplicate Advisory: Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-r7g4-qg5f-qqm2. This link is maintained to preserve external references.
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.
nodemailer <= 8.0.7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82662Medium· 6.5Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests
GHSA-r7g4-qg5f-qqm2Medium· 6.5Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
GHSA-6vj9-mwq6-2f5vMedium· 5.9Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
CVE-2026-100701Medium· 5.9Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername
GHSA-vm5r-23w9-m8hxHigh· 7.5Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
GHSA-prgh-xp8r-p3m5High· 7.5Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)