OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100700

HIGH · CVSS 7.5 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Nodemailer versions prior to 10.0.6 are vulnerable to a denial of service attack due to a flaw in the addressparser's regex pattern, which can lead to significant event loop blocking when processing malicious email headers. This vulnerability can result in prolonged service outages, making it critical for organizations using Nodemailer for email handling to prioritize immediate updates to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100700
Severity
HIGH
CVSS
7.5
EPSS
0.28%

Original NVD Description

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.