[Git][security-tracker-team/security-tracker][master] Add new node-nodemailer issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 10:37:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b3a9fb41 by Salvatore Bonaccorso at 2026-09-18T11:37:17+02:00
Add new node-nodemailer issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3247,13 +3247,24 @@ CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the multipart
CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0 ...)
NOT-FOR-US: Node joi
CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ...)
- TODO: check
+ - node-nodemailer 10.0.0+~8.0.1-1
+ NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148 (v9.1.0)
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e (v9.1.0)
CVE-2026-92597 (Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments ...)
- TODO: check
+ - node-nodemailer 10.0.0+~8.0.1-1
+ NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-cc9r-2j5m-2m83
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880 (v9.1.0)
CVE-2026-92596 (Nodemailer before 9.1.0 contains a quadratic time complexity vulnerabi ...)
- TODO: check
+ - node-nodemailer 10.0.0+~8.0.1-1
+ NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434 (v9.1.0)
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e (v9.1.0)
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150 (v9.1.0)
+ NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f (v9.1.0)
CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ...)
- TODO: check
+ - node-nodemailer 10.0.0+~8.0.1-1
+ NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8m3c-c648-2xjj
CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authori ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-92593 (Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix fo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3a9fb41b2ec93faabc8ad7ac49080b3bc61254e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3a9fb41b2ec93faabc8ad7ac49080b3bc61254e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/6464cf4e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list