{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92597","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-16T13:48:49.970Z","datePublished":"2026-09-16T21:47:01.599Z","dateUpdated":"2026-09-17T19:23:22.319Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-16T21:47:01.599Z"},"datePublic":"2026-09-01T00:00:00.000Z","title":"Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment","descriptions":[{"lang":"en","value":"Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as user@good-corp.com(x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registrable domain comevil.com, which an attacker can register) and used for both the SMTP envelope (RCPT TO) and the emitted To:/From: headers, while a conformant RFC 5322 parser terminates the domain at the comment and reads good-corp.com. An application that validates the recipient domain with a strict RFC 5322 parser (without inspecting parse defects) or a naive prefix/substring allow-list and then hands the raw address to Nodemailer can be induced to deliver mail to a domain the attacker controls. Fixed in 9.1.0."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Interpretation Conflict","cweId":"CWE-436","type":"CWE"}]}],"affected":[{"vendor":"nodemailer","product":"nodemailer","defaultStatus":"unaffected","packageURL":"pkg:npm/nodemailer","versions":[{"version":"6.9.16","status":"affected","versionType":"semver","lessThan":"9.1.0"},{"version":"9.1.0","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9.16","versionEndExcluding":"9.1.0"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":8.3,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-cc9r-2j5m-2m83","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-cc9r-2j5m-2m83)"},{"url":"https://github.com/nodemailer/nodemailer/commit/902b63e","tags":["patch"],"name":"Patch Commit"},{"name":"VulnCheck Advisory: Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/nodemailer-before-9.1.0-email-domain-validation-bypass-via-rfc-5322-comment"}],"credits":[{"lang":"en","value":"e1abrador","type":"reporter"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T19:17:07.433374Z","id":"CVE-2026-92597","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T19:23:22.319Z"}}]}}