AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-82662.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

### Summary Nodemailer disables TLS certificate verification in its internal HTTPS fetch client through the use of rejectUnauthorized: false inside lib/fetch/index.js. As a result, OAuth2 token requests trust invalid or self-signed HTTPS certificates and transmit sensitive OAuth credentials over connections that should fail TLS validation. An attacker in a machine-in-the-middle position can intercept OAuth2 credential exchanges and capture: - OAuth client_secret - refresh_token - access tokens The issue was verified through runtime testing using a self-signed HTTPS OAuth endpoint. ### Details Root Cause The issue originates from the internal HTTPS fetch implementation used by Nodemailer for OAuth2 token retrieval and related outbound HTTPS requests. Inside: `lib/fetch/index.js` the request options contain: `rejectUnauthorized: false` This disables TLS peer certificate verification globally for the internal HTTPS client unless explicitly overridden through optional TLS configuration. As a result: - self-signed certificates are trusted - invalid CA chains are accepted - hostname validation is bypassed - attacker-controlled HTTPS endpoints are treated as trusted This violates expected

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-r7g4-qg5f-qqm2

Open original source · Updated Oct 05, 2026

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

Source severity: HIGH / 8.3

EcosystemPackageAffected rangeFirst patched
npmnodemailer8.0.8

Original records & references

PUBLISHED 2026-06-15T13:34:48-04:00
MODIFIED 2026-10-05T18:51:58-04:00
INGESTED 2026-10-06T11:45:33-04:00