---
id: GHSA-vm5r-23w9-m8hx
title: >-
  Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined
  addresses enables a remote DoS (reachable via mailparser)
summary: >-
  Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined
  addresses enables a remote DoS (reachable via mailparser)
severity: high
cvss: 7.5
cwe:
  - CWE-407
vendor: nodemailer
product: nodemailer
ecosystem: npm
affected:
  - 'nodemailer >= 9.1.0, <= 10.0.4'
published: '2026-09-13'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T23:30:02Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-vm5r-23w9-m8hx'
references:
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90776'
  - url: >-
      https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89
  - url: 'https://github.com/nodemailer/nodemailer'
  - url: >-
      https://github.com/nodemailer/nodemailer/blob/v10.0.4/src/addressparser/index.ts#L251
  - url: 'https://github.com/nodemailer/nodemailer/releases/tag/v10.0.5'
  - url: >-
      https://www.vulncheck.com/advisories/nodemailer-9.1.0-through-10.0.4-denial-of-service-via-quadratic-address-parsing
  - url: 'https://github.com/advisories/GHSA-vm5r-23w9-m8hx'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-05T23:36:21.164Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-prgh-xp8r-p3m5. This link is maintained to preserve external references.

## Original Description
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.

## Affected packages

- `nodemailer >= 9.1.0, <= 10.0.4`

## Remediation

Refer to the advisory for the patched release.
