PT-2026-83722 · Npm · Nodemailer
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
nodemailer versions prior to 6.9.9
Description
A Regular Expression Denial of Service (ReDoS) occurs during email parsing when the
attachDataUrls parameter is enabled or when processing embedded file attachments. An attacker can send specially crafted emails containing malicious data URLs or embedded attachments to cause the event loop to hang, resulting in a denial of service. The issue is triggered within the processDataUrl() and convertDataImages() functions during the compilation and attachment processing stages.Recommendations
Update to version 6.9.9 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nodemailer