THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cc9r-2j5m-2m83 (medium) — Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

[GHSA] GHSA-cc9r-2j5m-2m83 (medium) — Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

medgithub_advisoriesPublished 2026-09-08

GHSA-cc9r-2j5m-2m83 Severity: medium CVE: None

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

### Summary

Nodemailer's email-address parser treats an **RFC 5322 comment** `( ... )` inside the domain as a point to **concatenate** the surrounding text, rather than as folding whitespace (CFWS) that **terminat

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cc9r-2j5m-2m83