CVE-2026-100702EPSS p14.9%
CVE-2026-100702CVE-2026-100702
Description
Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.
Scoring
| CVSS | 5.9 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.25% probability of exploitation · percentile 14.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |