CVE-2026-82659 | Nodemailer up to 9.0.0 Raw Option path/href server-side request forgery

SecurityVulns

A vulnerability was found in Nodemailer up to 9.0.0. It has been rated as critical. The affected element is an unknown function of the component Raw Option Handler. The manipulation of the argument path/href leads to server-side request forgery.

This vulnerability is documented as CVE-2026-82659. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More