GHSA-8vvx-rff5-p5rq: Stack Exhaustion Denial of Service via Nested Recipient Arrays in Nodemailer
Vulnerability ID: GHSA-8VVX-RFF5-P5RQ
CVSS Score: 5.9
Published: 2026-09-29
An uncontrolled recursion vulnerability exists in Nodemailer versions up to and including 10.0.1. When parsing recipient email addresses, recursively nested arrays bypass the parser's depth limit, resulting in V8 call stack exhaustion and immediate synchronous process termination.
TL;DR
Nodemailer versions <= 10.0.1 are vulnerable to a synchronous Denial of Service crash. Sending deeply nested arrays in recipient fields (such as 'to') causes a stack overflow in the V8 engine, crashing the application.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-674
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 5.9 (Medium)
- Impact: Denial of Service (DoS) via Stack Exhaustion
- Exploit Status: PoC Available
- KEV Status: Not Listed
- Vulnerable Component: MimeNode._parseAddresses / addressparser
Affected Systems
- Nodemailer npm package
Mitigation Strategies
- Upgrade Nodemailer to version 10.0.2 or higher to ensure native iterative array processing.
- Enforce rigorous schema validation (e.g., Zod or Joi) on incoming API requests to reject multi-dimensional or nested array structures.
- Pre-flatten and sanitize recipient lists in application space before invoking sendMail.
Remediation Steps:
- Run 'npm install nodemailer@10.0.2' or 'npm update nodemailer' to retrieve the patched version.
- Review code entry points where email endpoints receive inputs, implementing input filters that ensure 'to', 'cc', and 'bcc' properties are strictly flat arrays of valid email strings or simple strings.
- Verify the application handles downstream asynchronous processing exceptions correctly.
References
Read the full report for GHSA-8VVX-RFF5-P5RQ on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)