Bug 2526199 (CVE-2026-82662) - CVE-2026-82662 nodemailer: Nodemailer: Information disclosure due to disabled TLS certificate verification
Summary: CVE-2026-82662 nodemailer: Nodemailer: Information disclosure due to disabled...
Keywords:
Status: NEW
Alias: CVE-2026-82662
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-31 09:05 UTC by OSIDB Bzimport
Modified: 2026-09-18 06:58 UTC (History)
20 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-31 09:05:16 UTC
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.


Note You need to log in before you can comment on or make changes to this bug.