OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-100702 (CVSS 8.2)

NVD · officialPublished Sep 26, 2026Risk 37/100

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.

CVSS
8.2
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source