Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-82662

Опубликовано: 31 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

EPSS

Процентиль: 2%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
redhat
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
debian
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...

CVSS3: 6.5
github
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

EPSS

Процентиль: 2%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295