CVE-2026-100702
MediumAdvisory
Published 29 Sept 2026In the index since 30 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.003
- 15th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 204
- of 17,957 indexed, latest versions
- Container images
- 188
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
Carried by container images the latest versions of 204 of 17,957 indexed charts deploy, on 188 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nodemailernpm | 1.11.0, 2.7.2, 4.0.1, 4.6.8+52 more | 10.0.2 | 188 |
- OSV records
- GHSA-8vvx-rff5-p5rq
Charts affected
204 by stars
Container images carrying it
188 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.