{"id":"CVE-2026-100702","published":"2026-09-26T14:16:55.280","lastModified":"2026-09-27T00:16:34.667","description":"Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.","cvssScore":5.9,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-674"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq","tags":[]},{"url":"https://www.vulncheck.com/advisories/nodemailer-before-10.0.2-stack-exhaustion-via-nested-recipient-arrays","tags":[]}],"exploitRefs":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq","tags":[]}],"hasPoc":true,"ai":null}