DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-V53P-9FQP-M79J: GHSA-V53P-9FQP-M79J: Regular Expression Denial of Service (ReDoS) in Nodemailer addressparser

GHSA-V53P-9FQP-M79J: Regular Expression Denial of Service (ReDoS) in Nodemailer addressparser

Vulnerability ID: GHSA-V53P-9FQP-M79J
CVSS Score: 7.5
Published: 2026-09-29

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Nodemailer's addressparser fallback engine before version 10.0.6. Under specific malformed inputs with excessive word boundaries, the parser exhibits quadratic backtracking, leading to high CPU utilization and event loop blockage.

TL;DR

A ReDoS vulnerability in Nodemailer before 10.0.6 allows unauthenticated attackers to cause a remote denial of service by sending crafted email headers that block the single-threaded Node.js event loop.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1333
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.5 (High)
  • Impact: Remote Denial of Service (DoS)
  • Exploit Status: Proof-of-Concept (PoC)
  • KEV Status: Not Listed

Affected Systems

  • Nodemailer
  • Node.js applications processing emails
  • nodemailer: < 10.0.6 (Fixed in: 10.0.6)

Code Analysis

Commit: 437d7fc

fix(addressparser): scan free text for an address in linear time

Exploit Details

  • GitHub Advisory: Documented vulnerability disclosure with structural ReDoS payload patterns and benchmark stats.

Mitigation Strategies

  • Upgrade to Nodemailer 10.0.6 or higher
  • Implement strict length validation on email headers at the API gateway layer
  • Deploy WAF rules to drop excessively large non-whitespace header sequences

Remediation Steps:

  1. Execute 'npm install nodemailer@10.0.6' or 'yarn add nodemailer@10.0.6'
  2. Audit the package lockfile to ensure transitive dependencies are resolved to version 10.0.6+
  3. Implement header length checking logic prior to invoking mail dispatch functions

References


Read the full report for GHSA-V53P-9FQP-M79J on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)