Nodemailer

Nodemailer

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 13:23:57
  • Zuletzt bearbeitet 30.09.2026 16:32:17

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array...

  • EPSS 0.11%
  • Veröffentlicht 26.09.2026 13:23:57
  • Zuletzt bearbeitet 30.09.2026 16:32:17

Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same no...

  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 13:23:56
  • Zuletzt bearbeitet 30.09.2026 16:32:17

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs t...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 13:23:55
  • Zuletzt bearbeitet 30.09.2026 16:32:17

Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-se...

  • EPSS 0.26%
  • Veröffentlicht 16.09.2026 21:47:02
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with i...

  • EPSS 0.26%
  • Veröffentlicht 16.09.2026 21:47:01
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of...

  • EPSS 0.45%
  • Veröffentlicht 16.09.2026 21:47:00
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email w...

  • EPSS 0.2%
  • Veröffentlicht 16.09.2026 21:47:00
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the docum...

  • EPSS 0.48%
  • Veröffentlicht 13.09.2026 11:42:26
  • Zuletzt bearbeitet 24.09.2026 20:47:31

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to...

  • EPSS 1.13%
  • Veröffentlicht 31.08.2026 08:46:28
  • Zuletzt bearbeitet 10.09.2026 15:48:28

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatena...