PT-2026-83722 · Npm · Nodemailer

·

CVE-2024-58379

·

Published

2024-01-31

·

Updated

2026-09-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions nodemailer versions prior to 6.9.9
Description A Regular Expression Denial of Service (ReDoS) occurs during email parsing when the attachDataUrls parameter is enabled or when processing embedded file attachments. An attacker can send specially crafted emails containing malicious data URLs or embedded attachments to cause the event loop to hang, resulting in a denial of service. The issue is triggered within the processDataUrl() and convertDataImages() functions during the compilation and attachment processing stages.
Recommendations Update to version 6.9.9 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58379
GHSA-9H6G-PR28-7CQP

Affected Products

Nodemailer