Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks. | |
| Title | Nodemailer before 8.0.5 SMTP Command Injection via CRLF | |
| First Time appeared |
Nodemailer
Nodemailer nodemailer |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nodemailer
Nodemailer nodemailer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T11:00:28.826Z
Reserved: 2026-08-31T08:37:27.053Z
Link: CVE-2026-82853
Updated: 2026-08-31T11:00:18.511Z
Status : Received
Published: 2026-08-31T09:17:05.320
Modified: 2026-08-31T11:16:40.530
Link: CVE-2026-82853
No data.
OpenCVE Enrichment
Updated: 2026-08-31T11:30:04Z