nodemailer before 10.0.6 contains a denial of service...
High severity
Unreviewed
Published
Sep 26, 2026
to the GitHub Advisory Database
•
Updated Sep 26, 2026
Description
Published by the National Vulnerability Database
Sep 26, 2026
Published to the GitHub Advisory Database
Sep 26, 2026
Last updated
Sep 26, 2026
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.
References