Bug 2526199 (CVE-2026-82662)

Summary: CVE-2026-82662 nodemailer: Nodemailer: Information disclosure due to disabled TLS certificate verification
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, alizardo, dschmidt, jchui, jhe, jlanda, kaycoth, kshier, ktsao, lchilton, nboldt, oaljalju, psrna, rhel-process-autobot, sfeifer, simaishi, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Nodemailer where it disables Transport Layer Security (TLS) certificate verification. A remote attacker, positioned between the user and the server (a machine-in-the-middle attack), could exploit this by intercepting OAuth2 token requests. This allows the attacker to capture sensitive information, including OAuth client secrets, refresh tokens, and access tokens, leading to information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-31 09:05:16 UTC
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.