Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82661

Опубликовано: 31 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

A flaw was found in Nodemailer, an email sending library. This vulnerability allows a remote attacker with control over specific list comment parameters to inject arbitrary message headers into generated email messages. By failing to sanitize carriage return and line feed (CRLF) characters, an attacker can alter mail client behavior and message semantics, potentially leading to email spoofing or other integrity issues.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened Imagesgrafana13.2Not affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2526186nodemailer: Nodemailer: Header injection via unsanitized list comment fields

EPSS

Процентиль: 9%
0.0019
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

CVSS3: 5.4
nvd
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

CVSS3: 5.4
debian
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...

CVSS3: 5.4
github
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

EPSS

Процентиль: 9%
0.0019
Низкий

5.4 Medium

CVSS3