PT-2026-94114 · Npm · Nodemailer
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions 6.9.16 through 9.0.x
Description
Nodemailer mis-parses RFC 5322 comments within email addresses. In the
lib/addressparser component, when a comment is closed immediately before a non-break character, the tokenizer concatenates the surrounding atoms instead of treating the comment as folding whitespace (CFWS) that should terminate the domain. For example, an address like user@good-corp.com(x)evil.com is interpreted as good-corp.comevil.com rather than good-corp.com.This creates an interpretation conflict where an application using a strict RFC 5322 parser or a naive prefix/substring allow-list for domain validation may be deceived into believing an address is legitimate, while Nodemailer delivers the email to an attacker-controlled domain. This affects both the SMTP envelope
RCPT TO and the To:/From: headers. The root cause is located in the handleAddress function and the tokenizer's handling of the noBreak property in lib/addressparser/index.js.Recommendations
Update Nodemailer to version 9.1.0 or later.
As a temporary mitigation, avoid using naive prefix or substring allow-lists for email domain validation and ensure that any strict RFC 5322 parser used for validation is configured to inspect and reject parse defects.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nodemailer