{"id":"CVE-2026-100700","published":"2026-09-26T14:16:55.007","lastModified":"2026-09-28T16:17:10.847","description":"nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-407"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j","tags":[]},{"url":"https://www.vulncheck.com/advisories/nodemailer-before-10.0.6-denial-of-service-via-addressparser","tags":[]},{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j","tags":[]}],"exploitRefs":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j","tags":[]},{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j","tags":[]}],"hasPoc":true,"ai":null}