Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when processing RFC 5322 comments embedded in email addresses. An attacker can craft malicious email headers with comment-separated atoms that force the parser into exponential processing loops, consuming excessive CPU resources and blocking the Node.js event loop for several seconds. This causes denial of service against any application using vulnerable Nodemailer versions to parse untrusted email headers—including mail servers, email processing pipelines, and web applications that accept user-submitted email content. The vulnerability is particularly dangerous because it requires minimal attacker skill to exploit and can be triggered by sending a single specially-crafted email.
While CVE-2026-90776 maps to CWE-407 (Inefficient Algorithmic Complexity) rather than a specific MITRE ATT&CK technique, Casky practitioners can detect the attack patterns underlying this class of vulnerability through Claude's extended reasoning across resource exhaustion and input validation domains. A practitioner would observe detection signals related to Denial of Service (T1499) activities—specifically monitoring for anomalous CPU spikes correlated with email parsing operations, sustained event loop blocking in Node.js applications, and patterns of malformed RFC 5322 comment structures in email headers. Although Casky currently shows 0 directly mapped skills for this specific CVE, the platform's Claude-powered analysis would flag algorithmic complexity issues during code review of email parsing logic, detect suspicious email header patterns in traffic analysis, and correlate resource exhaustion metrics with email ingestion workflows—enabling practitioners to identify vulnerable Nodemailer deployments before active exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90776. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation