GHSA-vm5r-23w9-m8hxHigh· 7.5▾ TwilightDuplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-prgh-xp8r-p3m5. This link is maintained to preserve external references.
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.
nodemailer >= 9.1.0, <= 10.0.4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-prgh-xp8r-p3m5High· 7.5Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
CVE-2026-90776High· 7.5Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments
GHSA-v53p-9fqp-m79jHigh· 7.5Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
GHSA-2x7j-588g-ccc2High· 7.5Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
CVE-2025-14874High· 7.5A flaw was found in Nodemailer
CVE-2026-100700High· 7.5nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior