CVE-2026-100700 HIGH
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Node.js / npm
Mô tả
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.
Chi tiết
| Trạng thái | Received |
| Điểm CVSS | 7.5 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Ngày công bố | 21:16 26/09/2026 |
| Ngày cập nhật | 23:17 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [disclosure@vulncheck.com] https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
- [disclosure@vulncheck.com] https://www.vulncheck.com/advisories/nodemailer-before-10.0.6-denial-of-service-via-addressparser
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 23:17 28/09/2026 | CREATED | cve | HIGH |