Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82662

Опубликовано: 31 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

A flaw was found in Nodemailer where it disables Transport Layer Security (TLS) certificate verification. A remote attacker, positioned between the user and the server (a machine-in-the-middle attack), could exploit this by intercepting OAuth2 token requests. This allows the attacker to capture sensitive information, including OAuth client secrets, refresh tokens, and access tokens, leading to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened Imagesgrafana13.2Not affected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2526199nodemailer: Nodemailer: Information disclosure due to disabled TLS certificate verification

EPSS

Процентиль: 2%
0.00124
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
nvd
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
debian
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...

CVSS3: 6.5
github
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

EPSS

Процентиль: 2%
0.00124
Низкий

6.5 Medium

CVSS3