Bug 2541849 (CVE-2026-100701)
| Summary: | CVE-2026-100701 nodemailer: nodemailer: Information disclosure via TLS servername cache confusion | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abarbaro, alizardo, dschmidt, ikhan, jchui, jhe, jlanda, kaycoth, kshier, ktsao, lchilton, nboldt, oaljalju, psrna, rbobbitt, rhel-process-autobot, sfeifer, simaishi, stcannon, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in nodemailer. In multi-tenant environments, a remote attacker can exploit a cache confusion vulnerability by priming the shared Domain Name System (DNS) cache with a custom Transport Layer Security (TLS) server name. Because cached entries overwrite subsequent connection configurations for the same host, the client sends an incorrect Server Name Indication (SNI) and validates the peer certificate against an attacker-controlled identity. This flaw leads to information disclosure, allowing the attacker to intercept mail traffic and capture sensitive Simple Mail Transfer Protocol (SMTP) credentials.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-26 13:35:35 UTC
|