{"id":"CVE-2026-82661","aliases":["GHSA-268h-hp4c-crq3"],"url":"https://o3.security/vulnerability/CVE-2026-82661","summary":"Nodemailer CRLF Injection via List-* Header Comments","details":"Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.","published":"2026-08-31T08:46:26.291Z","modified":"2026-09-12T03:31:01.727762769Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"nodemailer","fixedVersion":"8.0.9"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82661.json"},{"type":"ADVISORY","url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-268h-hp4c-crq3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82661"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nodemailer-crlf-injection-via-list-header-comments"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:31:01.727762769Z"}}