CVE-2026-38728
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
Published 2026-05-15. Last modified 2026-06-17.