Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82660

Опубликовано: 31 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

A flaw was found in Nodemailer, a module for sending emails. The jsonTransport component, responsible for handling message data, does not correctly enforce security options designed to prevent unauthorized file and URL access. A remote attacker could exploit this by sending specially crafted messages containing malicious file paths or URLs. This bypasses the intended security controls, potentially allowing the attacker to read sensitive local files or access external web resources, leading to unauthorized information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened Imagesgrafana13.2Not affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2526203nodemailer: Nodemailer: Information Disclosure via jsonTransport Access Control Bypass

EPSS

Процентиль: 9%
0.00189
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
nvd
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
debian
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...

CVSS3: 5.4
github
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

EPSS

Процентиль: 9%
0.00189
Низкий

5.4 Medium

CVSS3