CVE-2026-100702 HIGH

CVE-2026-100702: Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays

Vendor Nodemailer
Product nodemailer
Weakness CWE-674
Published September 26, 2026
Last update September 26, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.

Key dates

02Disclosure timeline

September 26, 2026 CVE published
September 26, 2026 Record updated