<Vulnerability name="CVE-2026-92596">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T21:47:00</PublicDate>
    <Bugzilla id="2536015" url="https://bugzilla.redhat.com/show_bug.cgi?id=2536015" xml:lang="en:us">
nodemailer: Nodemailer: Denial of Service in addressparser component
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1050</CWE>
    <Details xml:lang="en:us" source="Mitre">
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Nodemailer's addressparser component. This vulnerability, due to quadratic time complexity, allows a remote attacker to cause a Denial of Service (DoS). By sending a specially crafted email with a large, comma-separated list of addresses, the attacker can block the Node.js event loop, leading to high CPU consumption and freezing the process.
    </Details>
    <Statement xml:lang="en:us">
Important: Red Hat products utilizing the Nodemailer library's addressparser component are susceptible to a denial of service. A remote attacker can exploit a quadratic time complexity vulnerability by sending a crafted email with an excessively long, comma-separated address list, leading to high CPU consumption and freezing the Node.js process.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhdh/rhdh-hub-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>grafana</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana12.4</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana13.1</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana13.2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>ansible-automation-platform/bootc-automation-portal-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-92596
https://nvd.nist.gov/vuln/detail/CVE-2026-92596
https://github.com/nodemailer/nodemailer/commit/34da642
https://github.com/nodemailer/nodemailer/commit/7cc38af
https://github.com/nodemailer/nodemailer/commit/83b8c48
https://github.com/nodemailer/nodemailer/commit/9116da9
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-denial-of-service-via-addressparser
    </References>
</Vulnerability>