[Git][security-tracker-team/security-tracker][master] Add new node-nodemailer issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 10:37:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b3a9fb41 by Salvatore Bonaccorso at 2026-09-18T11:37:17+02:00
Add new node-nodemailer issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3247,13 +3247,24 @@ CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the multipart
 CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0 ...)
 	NOT-FOR-US: Node joi
 CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ...)
-	TODO: check
+	- node-nodemailer 10.0.0+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148 (v9.1.0)
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e (v9.1.0)
 CVE-2026-92597 (Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments  ...)
-	TODO: check
+	- node-nodemailer 10.0.0+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-cc9r-2j5m-2m83
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880 (v9.1.0)
 CVE-2026-92596 (Nodemailer before 9.1.0 contains a quadratic time complexity vulnerabi ...)
-	TODO: check
+	- node-nodemailer 10.0.0+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434 (v9.1.0)
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e (v9.1.0)
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150 (v9.1.0)
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f (v9.1.0)
 CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ...)
-	TODO: check
+	- node-nodemailer 10.0.0+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8m3c-c648-2xjj
 CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authori ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92593 (Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix fo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3a9fb41b2ec93faabc8ad7ac49080b3bc61254e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3a9fb41b2ec93faabc8ad7ac49080b3bc61254e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/6464cf4e/attachment.htm>


More information about the debian-security-tracker-commits mailing list