CVE-2026-82661 MEDIUM

CVE-2026-82661: Nodemailer CRLF Injection via List-* Header Comments

Vendor Nodemailer
Product nodemailer
Weakness CWE-93 · CRLF injection
Published August 31, 2026
Last update September 2, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

Key dates

02Disclosure timeline

August 31, 2026 CVE published
September 2, 2026 Record updated

Related vulnerabilities

04Related CVE