PT-2026-99372 · Npm · Nodemailer
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions 5.0.0 through 10.0.1
Description
Nodemailer uses a process-global DNS cache keyed only by the DNS host, but stores the caller-specific TLS servername within each entry. When two direct TLS/SMTPS transports configured with
secure: true resolve the same non-IP host using different tls.servername values, the first transport's servername is returned during a cache hit. This overwrites the second transport's configured value, causing Nodemailer to send an incorrect Server Name Indication (SNI) value and validate the peer certificate against the wrong identity. In multi-tenant services or SNI-routed SMTP gateways, an attacker capable of priming the cache can force a victim transport to connect to the attacker's TLS virtual host and accept the attacker's certificate, even when rejectUnauthorized: true is set, potentially disclosing the victim's SMTP credentials.Recommendations
Update Nodemailer to version 10.0.2.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nodemailer