Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 31 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks. | |
| Title | Nodemailer before 8.0.5 SMTP Command Injection via CRLF | |
| First Time appeared |
Nodemailer
Nodemailer nodemailer |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nodemailer
Nodemailer nodemailer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-31T08:46:27.706Z
Updated: 2026-08-31T11:00:28.826Z
Reserved: 2026-08-31T08:37:27.053Z
Link: CVE-2026-82853
Updated: 2026-08-31T11:00:18.511Z
Status : Received
Published: 2026-08-31T09:17:05.320
Modified: 2026-08-31T11:16:40.530
Link: CVE-2026-82853