Medium · 4.9 Node.js & npm GHSA-v53p-9fqp-m79j GHSA-8vvx-rff5-p5rq GHSA-6vj9-mwq6-2f5v GHSA-g57g-f23g-4646
Four Nodemailer Vulnerabilities: Denial-of-Service and TLS Identity Flaws Across Multiple Versions
Four separate advisories affecting the npm package nodemailer describe two denial-of-service issues in address parsing, a cross-tenant TLS identity confusion issue in the DNS cache, and a parser edge case that can produce a malformed envelope recipient. Fixes are available for all four.
AI summary
PatchBriefing is tracking four distinct security advisories published for nodemailer, a widely used Node.js email-sending library. The issues were disclosed close together and affect different parts of the library: the address-parsing logic used to interpret recipient fields, and the shared DNS resolution cache used by direct TLS/SMTPS connections. Each advisory has an assigned GHSA identifier, a CVSS score, and a fixed version. This briefing summarizes what was reported, who is affected, and what action is recommended.
What happened
Four advisories were published for nodemailer within a short time window. GHSA-v53p-9fqp-m79j describes a regular-expression backtracking issue in the address-parser's free-text fallback that can block the Node.js event loop for tens of seconds on a single crafted header value. GHSA-8vvx-rff5-p5rq describes a separate issue where deeply nested arrays passed as recipient values (to/cc/bcc) bypass the parser's existing nesting-depth protection and exhaust the JavaScript call stack, crashing the process with an uncaught exception if the application does not wrap sendMail() in exception handling. GHSA-6vj9-mwq6-2f5v describes a process-global DNS cache that stores a connection-specific TLS servername under a hostname-only cache key; when two transports in the same process share a DNS host but configure different TLS server names, the second transport can receive the first transport's cached servername, causing it to validate the wrong TLS certificate and potentially send SMTP credentials to an unintended endpoint. GHSA-g57g-f23g-4646 describes a parser edge case where a quoted local-part followed by an RFC 5322 comment and trailing text produces a malformed address (e.g. an address value containing a space-separated extra domain) that is passed into the SMTP envelope without further strict validation.
Technical cause
GHSA-v53p-9fqp-m79j: the free-text fallback regular expression in the address parser exhibits quadratic backtracking because its character class can be retried from every offset in a long whitespace-free run, each retry rescanning to the next '@' or end of string. GHSA-8vvx-rff5-p5rq: nodemailer's recipient input type formally permits arbitrarily nested arrays, but only the outermost array is flattened before the value reaches the address parser's Tokenizer, which coerces non-string input with native .toString(). Native Array.prototype.toString() recurses through every nested array level, exhausting the call stack at sufficient depth; this path never reaches the existing MAX_NESTED_GROUP_DEPTH protection because it does not involve RFC 5322 group string parsing. GHSA-6vj9-mwq6-2f5v: the shared DNS cache is keyed only by hostname, but each cache entry also stores the TLS servername supplied by whichever transport populated the cache first; on a cache hit, that stored servername is returned and used to overwrite the current transport's explicitly configured servername before the TLS connection is made. GHSA-g57g-f23g-4646: when a local-part is quoted, the address parser handles a trailing RFC 5322 comment differently than for unquoted local-parts, allowing domain-like text after the comment to remain in the parsed address value, which is then used directly as the SMTP envelope recipient.
Why it matters
Because Node.js is single-threaded, the two denial-of-service issues (GHSA-v53p-9fqp-m79j and GHSA-8vvx-rff5-p5rq) can stall or crash an entire process from a single crafted input, with no authentication required and no SMTP server needed to trigger them. The DNS cache issue (GHSA-6vj9-mwq6-2f5v) is of particular concern for multi-tenant services or SNI-routed SMTP gateways, where it could let one tenant cause a victim transport to validate the wrong TLS certificate and transmit its SMTP credentials to an unintended endpoint, even with certificate validation (rejectUnauthorized: true) enabled. The parser edge case (GHSA-g57g-f23g-4646) results in a malformed envelope recipient; the reporter explicitly did not confirm whether this leads to delivery to an unintended recipient on a real SMTP server, so its practical exploitability remains unverified.
Who is affected
Applications and services using nodemailer to send email are affected, with exposure depending on the specific issue: GHSA-v53p-9fqp-m79j affects anywhere inbound header values reach the address parser, including via the mailparser package, or wherever user-supplied strings are used as message addresses. GHSA-8vvx-rff5-p5rq affects applications that accept attacker-controlled or partially attacker-controlled recipient data as structured JSON/array values and forward it to sendMail() without enforcing their own nesting-depth limits, including email-sending HTTP APIs, queue-based notification workers, and multi-tenant systems. GHSA-6vj9-mwq6-2f5v affects long-running processes that create multiple direct TLS/SMTPS (secure: true) nodemailer transports sharing the same DNS hostname with different explicit TLS servername values; the STARTTLS upgrade path is not claimed vulnerable. GHSA-g57g-f23g-4646 affects applications that parse recipient addresses containing a quoted local-part followed by an RFC 5322 comment.
Affected versions
GHSA-v53p-9fqp-m79j: nodemailer versions up to and including 10.0.5, fixed in 10.0.6. GHSA-8vvx-rff5-p5rq: nodemailer versions before 10.0.2, with vulnerability confirmed by testing in 2.7.2, 3.0.0, 7.0.11, 9.1.1, and 10.0.1; fixed in 10.0.2. The reporter notes that versions earlier than 2.7.2 were not assessed and should not be assumed safe. GHSA-6vj9-mwq6-2f5v: nodemailer versions 5.0.0 up to but not including 10.0.2, with vulnerability confirmed by testing in 5.0.0 and 10.0.1; fixed in 10.0.2. GHSA-g57g-f23g-4646: nodemailer versions 9.1.0 up to but not including 10.0.9, fixed in 10.0.9.
Fixes and mitigation
Fixes are available for all four issues. GHSA-v53p-9fqp-m79j is fixed in nodemailer 10.0.6, which replaces the backtracking search with a single linear pass. GHSA-8vvx-rff5-p5rq is fixed in nodemailer 10.0.2. As a mitigation until updated, applications can validate that recipient values are flat strings or flat arrays before calling nodemailer, and wrap the complete synchronous sendMail() call in exception handling to prevent process termination. GHSA-6vj9-mwq6-2f5v is fixed in nodemailer 10.0.2. GHSA-g57g-f23g-4646 is fixed in nodemailer 10.0.9; downstream applications are also advised not to assume a parser-produced address is safe for SMTP delivery without their own validation.
Recommended action
Update nodemailer to version 10.0.9 or later, which incorporates the fixes for all four advisories described here (10.0.6, 10.0.2, and 10.0.9 respectively). Review application code that passes user-controlled data into sendMail(), particularly recipient fields, and ensure synchronous exceptions from sendMail() are caught. For services that run multiple nodemailer transports with direct TLS/SMTPS connections in the same process, review whether different transports share a DNS hostname with different TLS servername configurations until the fixed version is deployed.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
The four advisories carry different patchwire scores reflecting their distinct impact profiles. GHSA-v53p-9fqp-m79j scores highest (4.9, CVSS 7.5) because it is unauthenticated, requires no user interaction, and can stall an entire Node.js process via a single network-reachable input. GHSA-8vvx-rff5-p5rq (4.0, CVSS 5.9) is similarly unauthenticated and causes process crashes, but requires a higher attack-complexity precondition (structured array input reaching sendMail() unchecked). GHSA-g57g-f23g-4646 (3.7, CVSS 5.3) reflects a confirmed parsing flaw with unconfirmed real-world delivery impact. GHSA-6vj9-mwq6-2f5v (3.4, CVSS 5.9) has the lowest patchwire score among the four despite a confidentiality impact, because it requires low-privilege access and specific multi-tenant deployment conditions (shared DNS host, differing servername, SNI-based routing) to be exploitable. All four scores are computed from CVSS base score plus adjustments for exploitation status, user interaction, and fix availability; none of the four is known to be actively exploited or have public exploit code.
Affected versions
- nodemailer <= 10.0.5
- vulnerable
- ≥ 10.0.6
- patched
- nodemailer < 10.0.2
- vulnerable
- ≥ 10.0.2
- patched
- nodemailer >= 5.0.0, < 10.0.2
- vulnerable
- ≥ 10.0.2
- patched
- nodemailer >= 9.1.0, < 10.0.9
- vulnerable
- ≥ 10.0.9
- patched
Reported fixes
Fixes are available for all four issues. GHSA-v53p-9fqp-m79j is fixed in nodemailer 10.0.6, which replaces the backtracking search with a single linear pass. GHSA-8vvx-rff5-p5rq is fixed in nodemailer 10.0.2. As a mitigation until updated, applications can validate that recipient values are flat strings or flat arrays before calling nodemailer, and wrap the complete synchronous sendMail() call in exception handling to prevent process termination. GHSA-6vj9-mwq6-2f5v is fixed in nodemailer 10.0.2. GHSA-g57g-f23g-4646 is fixed in nodemailer 10.0.9; downstream applications are also advised not to assume a parser-produced address is safe for SMTP delivery without their own validation.
How this was built
4 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email