Home

Description

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components

PUBLISHED Reserved 2026-04-06 | Published 2026-05-15 | Updated 2026-05-15 | Assigner mitre

References

bytecreator.dev/blog/CVE-2026-38728 exploit

github.com/nodemailer/smtp-server

github.com/nodemailer/smtp-server/releases/tag/v3.18.3

bytecreator.dev/blog/CVE-2026-38728

cve.org (CVE-2026-38728)

nvd.nist.gov (CVE-2026-38728)

Download JSON