MEDIUMVulnerability

CVE-2026-82853

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for email spoofing and phishing attacks.

Properties

severity
MEDIUM
score
4.9
epss_score
0.00735
cve_id
CVE-2026-82853
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-31T09:17:05.320
last_modified
2026-09-10T15:48:28.757
epss_percentile
0.52533

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of CRLF Sequences ('CRLF Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82853 — Ninja Signal Threat Intelligence | Ninja Signal