CVE-2026-92595 | Nodemailer up to 9.1.0 Content Resolution MailMessage.resolveContent data/key/callback server-side request forgery

SecurityVulns

A vulnerability described as critical has been identified in Nodemailer up to 9.1.0. This issue affects the function MailMessage.resolveContent of the component Content Resolution. The manipulation of the argument data/key/callback results in server-side request forgery.

This vulnerability was named CVE-2026-92595. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More