PT-2026-94113 · Npm · Nodemailer
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions prior to 9.1.0
Description
Nodemailer contains a quadratic time complexity issue in its
addressparser component. When parsing a list of comma-separated addresses, the parser uses Array.prototype.concat to accumulate results, which causes the CPU consumption to grow proportionally to the square of the input length. This behavior blocks the single-threaded Node.js event loop, leading to 100% CPU usage and freezing the process, which results in a denial of service for all other requests.This issue can be triggered via structured-address headers such as
To, Cc, Bcc, From, or Reply-To, or by directly using the exported addressparser module. For example, an address value of approximately 1.5 MB can freeze the process for 25 to 30 seconds.Recommendations
Update Nodemailer to version 9.1.0 or later.
As a temporary mitigation, restrict the length of user-supplied address strings or limit the number of recipients allowed in email headers before they are processed by the parser.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nodemailer