DEBIAN-CVE-2026-82659

Source
https://security-tracker.debian.org/tracker/CVE-2026-82659
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-82659.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-82659
Upstream
Published
2026-08-31T09:17:03Z
Modified
2026-09-11T19:00:23Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

References

Affected packages

Debian:12 / node-nodemailer

Package

Name
node-nodemailer
Purl
pkg:deb/debian/node-nodemailer?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.8.0+~6.4.6-1
6.9.4+~6.4.9-1
6.9.4+~6.4.9-2
6.9.4+~6.4.9-3
6.9.4+~6.4.9-4
6.9.13+~6.4.14-1
6.9.15+~6.4.16-1
6.9.16+~6.4.16-1
6.10.0+~6.4.17-1
7.*
7.0.5+~7.0.1-1
7.0.6+~7.0.1-1
7.0.9+~7.0.2-1
7.0.9+~7.0.2-2
7.0.10+~7.0.2-1
7.0.12+~7.0.5-1
8.*
8.0.2+~7.0.11-1
8.0.3+~7.0.11-1
8.0.4+~7.0.11-1
8.0.4+~7.0.11-2
8.0.11+~8.0.1-1
9.*
9.0.0+~8.0.1-1
9.0.3+~8.0.1-1
9.0.5+~8.0.1-1
9.0.6+~8.0.1-1
10.*
10.0.0+~8.0.1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-82659.json"

Debian:13 / node-nodemailer

Package

Name
node-nodemailer
Purl
pkg:deb/debian/node-nodemailer?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.10.0+~6.4.17-1
6.10.0+~6.4.17-1+deb13u1
7.*
7.0.5+~7.0.1-1
7.0.6+~7.0.1-1
7.0.9+~7.0.2-1
7.0.9+~7.0.2-2
7.0.10+~7.0.2-1
7.0.12+~7.0.5-1
8.*
8.0.2+~7.0.11-1
8.0.3+~7.0.11-1
8.0.4+~7.0.11-1
8.0.4+~7.0.11-2
8.0.11+~8.0.1-1
9.*
9.0.0+~8.0.1-1
9.0.3+~8.0.1-1
9.0.5+~8.0.1-1
9.0.6+~8.0.1-1
10.*
10.0.0+~8.0.1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-82659.json"

Debian:14 / node-nodemailer

Package

Name
node-nodemailer
Purl
pkg:deb/debian/node-nodemailer?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.3+~8.0.1-1

Affected versions

6.*
6.10.0+~6.4.17-1
7.*
7.0.5+~7.0.1-1
7.0.6+~7.0.1-1
7.0.9+~7.0.2-1
7.0.9+~7.0.2-2
7.0.10+~7.0.2-1
7.0.12+~7.0.5-1
8.*
8.0.2+~7.0.11-1
8.0.3+~7.0.11-1
8.0.4+~7.0.11-1
8.0.4+~7.0.11-2
8.0.11+~8.0.1-1
9.*
9.0.0+~8.0.1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-82659.json"