๐Ÿ” CVE Alert

CVE-2026-92598

MEDIUM 6.5

Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.

CWE CWE-436
Vendor nodemailer
Product nodemailer
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for nodemailer nodemailer

Be the first to know when new medium vulnerabilities affecting nodemailer nodemailer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

nodemailer / nodemailer
0 < 9.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp github.com: https://github.com/nodemailer/nodemailer/commit/259c32d github.com: https://github.com/nodemailer/nodemailer/commit/b212ac4 vulncheck.com: https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-idn-punycode-domain-allow-list-bypass

Credits

๐Ÿ” e1abrador