PT-2026-99373 · Npm · Nodemailer
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions prior to 10.0.2
Description
Improper flattening of deeply nested arrays in recipient fields such as
to, cc, and bcc can lead to stack exhaustion. An attacker can provide a deeply nested JSON recipient array that triggers a recursive Array.toString() conversion, which exhausts the call stack and terminates the Node.js process.Recommendations
Update to version 10.0.2 or later.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nodemailer