Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-82659

16 дней назад

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-82659

16 дней назад

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-82659

16 дней назад

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-82659

16 дней назад

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-p6gq-j5cr-w38f

3 месяца назад

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2026-13686

3 месяца назад

Уязвимость метода MailComposer.compile() библиотеки для отправки писем Nodemailer, позволяющая нарушителю раскрыть защищаемую информацию и осуществить SSRF-атаку

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-82659

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
0%
Низкий
16 дней назад
redhat логотип
CVE-2026-82659

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-82659

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

CVSS3: 7.1
0%
Низкий
16 дней назад
debian логотип
CVE-2026-82659

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...

CVSS3: 7.1
0%
Низкий
16 дней назад
github логотип
GHSA-p6gq-j5cr-w38f

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

CVSS3: 7.1
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-13686

Уязвимость метода MailComposer.compile() библиотеки для отправки писем Nodemailer, позволяющая нарушителю раскрыть защищаемую информацию и осуществить SSRF-атаку

CVSS3: 7.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу