Nodemailer, Malformed Envelope Recipient via RFC 5322 Comment, CVE-2026-100699 (Medium) -DC-Sep2026-2653

Listen to this Post

Nodemailer’s address parser can produce an unexpected recipient address when an RFC 5322 comment follows the domain of an address whose local-part is a quoted string. For example, the input `”user”@example.com(x)evil.com` is parsed as { address: "[email protected] evil.com", name: "" }. The resulting address therefore contains additional attacker-controlled domain text separated by a literal space. The parsed `.address` value is subsequently propagated into the SMTP envelope: `src/addressparser/index.ts` → `recipient.address` → `src/mime-node/index.ts` → envelope.to. The envelope construction uses the parsed address without another strict address validation step. This appears to be a variant of the RFC 5322 comment parsing issue addressed by GHSA-cc9r-2j5m-2m83, but it follows a different parser path when the local-part is quoted. The issue is caused by different parsing behavior for quoted and unquoted local-parts. The quoted-local-part variant allows the comment-separated trailing domain atoms to remain in the resulting `.address` value. That value is then used when constructing the message envelope: envelope.to = recipients.map(to => to.address as string). No additional strict recipient validation is performed at this boundary. The confirmed impact is that attacker-controlled comment content can result in a malformed/ambiguous recipient address being accepted by the parser and propagated into envelope.to. The reporter did not confirm successful delivery to an unintended recipient through a real SMTP server using this exact quoted-local-part variant. The remaining question is how real SMTP servers and other Nodemailer transports handle an envelope recipient containing a value such as [email protected] evil.com. An end-to-end SMTP test is required to determine whether this parser behavior results in an exploitable delivery or recipient-validation bypass. This report is intended as a potential variant/follow-up to GHSA-cc9r-2j5m-2m83. The existing advisory addresses RFC 5322 comment handling in email domains. This report identifies a separate parser path involving quoted local-parts that can preserve additional domain-like content in the normalized address. Please evaluate whether this behavior is already covered by the existing fix or represents a remaining parser variant. The parser should consistently reject or correctly terminate addresses containing trailing domain atoms after RFC 5322 comments, regardless of whether the local-part is quoted. The envelope-generation layer should also avoid assuming that a parser-produced address is safe for SMTP delivery without appropriate validation.

DailyCVE Form:

Platform: Nodemailer
Version: 9.1.0-10.0.8
Vulnerability: Envelope Recipient
Severity: Medium
date: 2026-09-26

Prediction: 2026-09-26

What Undercode Say:

Install vulnerable version
npm install [email protected]
Test the parser
node -e "const nodemailer = require('nodemailer'); const parser = require('nodemailer/lib/addressparser'); console.log(parser('\"user\"@example.com(x)evil.com'));"
// Vulnerable code path in src/addressparser/index.ts
const address = "[email protected] evil.com";
const envelope = {
to: [bash] // No strict validation
};

Exploit: (Educational Purposes!)

// Craft a malicious recipient address
const maliciousAddress = '"user"@legitimate.com(x)attacker.com';
// The parser will produce an ambiguous envelope recipient
const parsed = addressparser(maliciousAddress);
// parsed[bash].address === "[email protected] attacker.com"
// This value is used directly in the SMTP envelope
envelope.to = parsed.map(p => p.address);

Protection: from this CVE

Upgrade to patched version
npm install [email protected]
// Validate addresses after parsing
const parsed = addressparser(input);
const isValid = parsed.every(p => /^[^\s@]+@[^\s@]+.[^\s@]+$/.test(p.address));
if (!isValid) throw new Error('Invalid recipient address');

Impact:

Potential email misdelivery, recipient-validation bypass, and ambiguity in logging/auditing systems.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top