[Git][security-tracker-team/security-tracker][master] Add new node-nodemailer issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 21:00:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
65feca10 by Salvatore Bonaccorso at 2026-09-26T21:59:40+02:00
Add new node-nodemailer issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -68,13 +68,21 @@ CVE-2026-100704 (Kyverno is a policy engine for Kubernetes. In versions 1.14.0 t
 CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL libr ...)
 	NOT-FOR-US: Kyverno
 CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply nested array ...)
-	TODO: check
+	- node-nodemailer 10.0.10+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/ebe084940aef88278afc6016b78c6d1c3821bb66 (v10.0.2)
 CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cach ...)
-	TODO: check
+	- node-nodemailer 10.0.10+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-6vj9-mwq6-2f5v
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/a6512dbcb3c6e7f2f70d3acccc5752defe3c61fe (v10.0.2)
 CVE-2026-100700 (nodemailer before 10.0.6 contains a denial of service vulnerability in ...)
-	TODO: check
+	- node-nodemailer 10.0.10+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/437d7fc47403df176bc39271641541b7a9bce102 (v10.0.6)
 CVE-2026-100699 (Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 an ...)
-	TODO: check
+	- node-nodemailer 10.0.10+~8.0.1-1
+	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-g57g-f23g-4646
+	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/2f36eb1aa1dd33e312411dc9b888548e14db54ee (v10.0.9)
 CVE-2026-100698 (Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' strin ...)
 	TODO: check
 CVE-2026-100697 (Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65feca108b4f4adaea6bf8590d1ac460ebd2caed

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/65feca108b4f4adaea6bf8590d1ac460ebd2caed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/78d437fa/attachment.htm>


More information about the debian-security-tracker-commits mailing list