StackRadar

CVE-2026-92598

Medium

Advisory

Published 8 Sept 2026In the index since 18 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
19th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
188
of 17,803 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

Carried by container images the latest versions of 188 of 17,803 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
nodemailernpm1.11.0, 2.7.2, 4.0.1, 4.6.8+49 more9.1.0174
OSV records
GHSA-wmmp-3585-3rmp

Charts affected

188 by stars
ChartLatestAffected imagesRadar Score
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
nodemailer@8.0.10
9.1.0

Open the chart page →

1,050
xyopsquench-xyopsVerified publisher0.0.121 of 1See more

xyops quench-xyops 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/xyopsdigest-pinneddd7d8bf3b654
nodemailer@9.0.1
9.1.0

Open the chart page →

79
etherpadredhat-cop0.0.81 of 1See more

etherpad redhat-cop 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
etherpad/etherpad:latest6020e7b57f4b
nodemailer@9.0.3
9.1.0

Open the chart page →

908
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
nodemailer@7.0.6
9.1.0

Open the chart page →

4,808
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
nodemailer@6.9.16
9.1.0

Open the chart page →

15,770
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
nodemailer@7.0.13
9.1.0

Open the chart page →

69,552
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
nodemailer@6.9.15
9.1.0
fonoster/routr-dispatcher:2.13.65f8f380dc174
nodemailer@6.9.15
9.1.0
fonoster/routr-location:2.13.6051ba9c34ef5
nodemailer@6.9.15
9.1.0
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
nodemailer@6.9.15
9.1.0
fonoster/routr-registry:2.13.6e27001f2813c
nodemailer@6.9.15
9.1.0

Open the chart page →

11,072
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
nodemailer@7.0.4
9.1.0

Open the chart page →

5,359
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
nodemailer@6.9.13
9.1.0

Open the chart page →

1,734
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
nodemailer@6.9.13
9.1.0

Open the chart page →

7,500
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
nodemailer@7.0.13
9.1.0

Open the chart page →

30,706
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
nodemailer@6.6.5
9.1.0

Open the chart page →

4,794
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
nodemailer@7.0.10
9.1.0

Open the chart page →

4,745
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
nodemailer@6.9.1
9.1.0

Open the chart page →

4,444
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
nodemailer@6.4.6
9.1.0

Open the chart page →

3,661
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
nodemailer@6.9.16
9.1.0

Open the chart page →

2,005
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
nodemailer@8.0.11
9.1.0

Open the chart page →

3,085
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
nodemailer@6.9.9
9.1.0

Open the chart page →

16,564
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
nodemailer@6.9.9
9.1.0

Open the chart page →

16,597
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
nodemailer@6.7.5
9.1.0

Open the chart page →

14,827
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
nodemailer@6.9.9
9.1.0

Open the chart page →

16,597
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
nodemailer@6.9.9
9.1.0

Open the chart page →

14,369
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
nodemailer@6.9.9
9.1.0

Open the chart page →

14,369
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
nodemailer@6.9.9
9.1.0

Open the chart page →

16,216
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
nodemailer@6.9.9
9.1.0

Open the chart page →

15,814
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
nodemailer@6.9.9
9.1.0

Open the chart page →

11,260
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
nodemailer@8.0.11
9.1.0

Open the chart page →

689
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
nodemailer@6.7.3
9.1.0

Open the chart page →

4,037
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
nodemailer@6.10.1
9.1.0

Open the chart page →

5,650
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
nodemailer@9.0.1
9.1.0

Open the chart page →

5,634
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
nodemailer@7.0.13
9.1.0

Open the chart page →

2,041
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
nodemailer@6.10.0
9.1.0

Open the chart page →

5,282
devportalveecode-platform-nextVerified publisher0.1.231 of 1See more

devportal veecode-platform-next 0.1.23

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinneda72cf5cb47b8
nodemailer@8.0.11
9.1.0

Open the chart page →

1,840
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
nodemailer@6.7.2
9.1.0

Open the chart page →

3,142
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
nodemailer@8.0.4
9.1.0

Open the chart page →

2,237
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
nodemailer@6.9.9
9.1.0

Open the chart page →

6,485
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
nodemailer@6.9.1
9.1.0

Open the chart page →

5,525
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-92598.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
nodemailer@6.9.15
9.1.0

Open the chart page →

6,350

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
nodemailer@6.9.15
9.1.0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
nodemailer@9.0.1
9.1.0
1
ibmcom/microclimate-portal:latested5505e5c7ec
nodemailer@2.7.2
9.1.0
1
jayfong/yapi:1.10.2163e5d621910
nodemailer@4.0.1
9.1.0
1
joplin/server:latest3f7b852959aa
nodemailer@6.10.1
9.1.0
1
joplin/server:3.0-beta52af57880c0e
nodemailer@6.9.13
9.1.0
1
joplin/server:2.14.2-betab87564ef34e9
nodemailer@6.9.7
9.1.0
1
library/ghost:6.37.01ef2e532ca4d
nodemailer@8.0.5
9.1.0
1
library/ghost:6.25.12654b1e90413
nodemailer@6.10.1
9.1.0
1
library/ghost:6.41.129773d6be407
nodemailer@8.0.5
9.1.0
1
library/ghost:4.37.0767230c0f263
nodemailer@6.7.2
9.1.0
1
library/ghost:6.39.0-alpine77196da4b0df
nodemailer@8.0.5
9.1.0
1
library/ghost:5.79.083f7bf209844
nodemailer@6.9.9
9.1.0
1
library/ghost:6.64.0a31d03f1f629
nodemailer@8.0.11
9.1.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
nodemailer@6.10.1
9.1.0
1
library/kibana:7.17.150172f1c538e7
nodemailer@6.6.2
9.1.0
1
library/kibana:8.18.004c0fc150f3a
nodemailer@6.9.15
9.1.0
1
library/kibana:7.17.8c5781ba340ef
nodemailer@6.6.2
9.1.0
1
library/kibana:7.17.3e2e2031c15be
nodemailer@6.6.2
9.1.0
1
linuxserver/overseerr:1.35.06108ed066d4a
nodemailer@6.8.0
9.1.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
nodemailer@7.0.13
9.1.0
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
nodemailer@6.6.5
9.1.0
1
louislam/uptime-kuma:13d632903e6af
nodemailer@6.9.16
9.1.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
nodemailer@6.9.16
9.1.0
1
louislam/uptime-kuma:2.4.091e963bfda56
nodemailer@7.0.13
9.1.0
1
louislam/uptime-kuma:1.23.1396510915e6be
nodemailer@6.9.13
9.1.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
nodemailer@6.9.16
9.1.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
nodemailer@6.6.5
9.1.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
nodemailer@6.6.5
9.1.0
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
nodemailer@6.9.13
9.1.0
1
maildev/maildev:2.2.1180ef51f65ee
nodemailer@6.9.14
9.1.0
1
misskey/misskey:12.110.1e08b7c478093
nodemailer@6.7.3
9.1.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
nodemailer@6.9.8
9.1.0
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
nodemailer@6.9.7
9.1.0
1
n8nio/n8n:2.38.45d9f0cc5672b
nodemailer@8.0.10
9.1.0
1
n8nio/n8n:2.25.7761374d4eb84
nodemailer@7.0.11
9.1.0
1
n8nio/n8n:1.86.08b39ed5a2de9
nodemailer@6.9.9
9.1.0
1
n8nio/n8n:0.212.0a9195bc499a3
nodemailer@6.8.0
9.1.0
1
n8nio/n8n:2.39.5cfa04788a34a
nodemailer@8.0.10
9.1.0
1
n8nio/n8n:2.36.8cfe2704ff858
nodemailer@8.0.10
9.1.0
1
n8nio/n8n:1.33.1dd171d45102a
nodemailer@6.9.9
9.1.0
1
n8nio/n8n:1.115.1ed16e560c40e
nodemailer@6.9.9
9.1.0
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
nodemailer@2.7.2
9.1.0
1
nocodb/nocodb:latest4b760f0d2547
nodemailer@9.0.5
9.1.0
1
nocodb/nocodb:0.258.06779a4ddedf2
nodemailer@6.9.16
9.1.0
1
nocodb/nocodb:0.301.5d9516f0bf546
nodemailer@7.0.13
9.1.0
1
nodered/node-red-docker:0.19.6-v8070643219ea2
nodemailer@1.11.0
9.1.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
nodemailer@6.7.2
9.1.0
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
nodemailer@6.4.18
9.1.0
1
outlinewiki/outline:0.82.0494dfb9249a6
nodemailer@6.10.0
9.1.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.