DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-G57G-F23G-4646: GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser

GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser

Vulnerability ID: GHSA-G57G-F23G-4646
CVSS Score: 6.5
Published: 2026-09-29

Nodemailer versions prior to 10.0.9 are vulnerable to a parser differential bug. When processing a quoted local-part followed by an RFC 5322 comment and trailing characters, the internal addressparser module fails to order its normalization routine correctly. This error results in the generation of malformed envelope recipient addresses containing injected whitespace and secondary domains, allowing attackers to bypass routing restrictions and exfiltrate sensitive emails.

TL;DR

A parser logic flaw in Nodemailer allows attackers to inject secondary domains and spaces into email envelopes, leading to routing bypasses and email interception.


⚠️ Exploit Status: POC

Technical Details

  • Vulnerability Type: Parser Differential / SMTP Parameter Injection
  • CWE ID: CWE-20
  • Attack Vector: Network / Input-driven
  • Affected Component: src/addressparser/index.ts
  • Exploit Status: Proof of Concept
  • Remediation Status: Official Patch Available (v10.0.9)

Affected Systems

  • Node.js applications using Nodemailer for SMTP transport
  • Upstream systems relying on domain-level email whitelisting
  • nodemailer: < 10.0.9 (Fixed in: 10.0.9)

Code Analysis

Commit: 2f36eb1

Fix address parsing logic regarding quoted local-parts and comments

Exploit Details

Mitigation Strategies

  • Upgrade Nodemailer to version 10.0.9 or higher
  • Implement strict upstream validation filtering out parenthesis and quotes in user email submissions
  • Configure the Mail Transfer Agent (MTA) to reject SMTP envelopes containing whitespace or malformed recipient fields

Remediation Steps:

  1. Run npm install nodemailer@10.0.9 to update the package
  2. Verify the dependency tree using npm list nodemailer
  3. Deploy upstream input validation filters as a defense-in-depth measure

References


Read the full report for GHSA-G57G-F23G-4646 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)