CVE-2026-92596
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
취약점 유형
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
참고 자료
- https://github.com/nodemailer/nodemailer/commit/34da642
- https://github.com/nodemailer/nodemailer/commit/7cc38af
- https://github.com/nodemailer/nodemailer/commit/83b8c48
- https://github.com/nodemailer/nodemailer/commit/9116da9
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
- https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-denial-of-service-via-addressparser
공격자보다 먼저 취약점을 찾으세요.
GitHub로 로그인하고 1분 안에 첫 감사를 실행하세요. 무료 플랜은 신용카드가 필요 없습니다.