<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 14:51:58 +0000</lastBuildDate>
    <item>
      <title>GHSA-cc9r-2j5m-2m83 — Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cc9r-2j5m-2m83</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Nodemailer&amp;#39;s email-address parser treats an **RFC 5322 comment** `( ... )` inside the domain as a point to **concatenate** the surrounding text, rather than as folding whitespace (CFWS) that **terminates** the domain. Consequently a recipient address such as `user@good-corp.com(x)evil.com` is parsed and **delivered to `good-corp.comevil.com`** (registrable domain `comevil.com`, attacker‑controlled), while a conformant RFC 5322 parser terminates the domain at the comment and reads `good-corp.com`.&lt;/p&gt;
&lt;p&gt;An application that decides *whether it is allowed to email a recipient* by parsing/validating the recipient&amp;#39;s domain — with a strict RFC 5322 parser (used without inspecting parse defects) or with a naive prefix/substring allow‑list — and then hands the raw address to Nodemailer for delivery, can be induced to send mail to a domain the attacker controls. This is an **Interpretation Conflict (CWE‑436)**, the same class as CVE‑2025‑13033, reached through the RFC 5322 *comment* construct (the &amp;#34;Comments&amp;#34; technique in PortSwigger&amp;#39;s *Splitting the email atom* research, which produced a Postfix fix).&lt;/p&gt;
&lt;p&gt;Severity is **Moderate**: exploitation requires the app&amp;#39;s domain check to disagree with Nodemailer (see **Impact** for exactly which parsers do and do not). Verified end‑to‑end against a real RFC 5321 SMTP server (nodemailer 9.0.6 → `aiosmtpd`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Root cause is in `lib/addressparser/index.js`.&lt;/p&gt;
&lt;p&gt;1. The tokenizer registers the comment as an operator pair (`Tokenizer.o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Nodemailer&amp;#39;s email-address parser treats an **RFC 5322 comment** `( ... )` inside the domain as a point to **concatenate** the surrounding text, rather than as folding whitespace (CFWS) that **terminates** the domain. Consequently a recipient address such as `user@good-corp.com(x)evil.com` is parsed and **delivered to `good-corp.comevil.com`** (registrable domain `comevil.com`, attacker‑controlled), while a conformant RFC 5322 parser terminates the domain at the comment and reads `good-corp.com`.&lt;/p&gt;
&lt;p&gt;An application that decides *whether it is allowed to email a recipient* by parsing/validating the recipient&amp;#39;s domain — with a strict RFC 5322 parser (used without inspecting parse defects) or with a naive prefix/substring allow‑list — and then hands the raw address to Nodemailer for delivery, can be induced to send mail to a domain the attacker controls. This is an **Interpretation Conflict (CWE‑436)**, the same class as CVE‑2025‑13033, reached through the RFC 5322 *comment* construct (the &amp;#34;Comments&amp;#34; technique in PortSwigger&amp;#39;s *Splitting the email atom* research, which produced a Postfix fix).&lt;/p&gt;
&lt;p&gt;Severity is **Moderate**: exploitation requires the app&amp;#39;s domain check to disagree with Nodemailer (see **Impact** for exactly which parsers do and do not). Verified end‑to‑end against a real RFC 5321 SMTP server (nodemailer 9.0.6 → `aiosmtpd`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Root cause is in `lib/addressparser/index.js`.&lt;/p&gt;
&lt;p&gt;1. The tokenizer registers the comment as an operator pair (`Tokenizer.o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cc9r-2j5m-2m83</guid>
    </item>
  </channel>
</rss>
