mediumCVSS 5.9Vulnerability

GHSA-6vj9-mwq6-2f5v

### Summary Nodemailer's process-global DNS cache is keyed only by `host`, but each cache entry also stores the caller-specific TLS `servername`. When two direct SMTPS transports use the same DNS host with different `tls.servername` values, the first transport's server name is returned to the second transport and overwrites its explicitly configured value. As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with `rejectUnauthorized: true`, and sends the victim's SMTP credentials to it. ## Affected component - **Ecosystem:** npm - **Package:** `nodemailer` - **Repository:** https://github.com/nodemailer/nodemailer - **Tested version:** `10.0.1` - **Tested commit:** `40d52215aac65b811d7e131bc916f68605efd9d2` - **Runtime-confirmed vulnerable versions:** `5.0.0` and `10.0.1` - **Affected versions:** `>= 5.0.0, <= 10.0.1` - **Patched versions:** None known at the time of this report - **Affected mode:** Direct TLS/SMTPS connections (`secure: true`) where different transports use the same non-IP `host` and different TLS `servername` values The vulnerable cache implementation was introduced in commit `6859b5dd96c8d9f0070a3169a877181b71df4a3b` on 2018-12-28. Git history shows `v5.0.0` as the first release tag containing that commit. The behavior remains present in `v10.0.1`. ## Details ### Root cause `src/shared/index.ts` defines one module-global DNS cache, keyed only by the DNS host: ```ts export const dnsCache = new Map<string, DnsCacheEntry>(); ``` Although the cache key contains only `host`, the cached value contains both DNS addresses and the request-specific TLS identity: ```ts const value: DnsCacheValue = { addresses: allAddresses, servername: options.servername || host }; dnsCache.set(host, { v

Properties

severity
medium
summary
Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
cvss_score
5.9
retrieved_at
2026-09-29T00:57:22+00:00
ghsa_published
2026-09-28T21:56:05Z
source_url
https://github.com/advisories/GHSA-6vj9-mwq6-2f5v
ghsa_updated
2026-09-28T21:57:00Z
ghsa_id
GHSA-6vj9-mwq6-2f5v
last_source
GitHub Advisory Database
cve_id
GHSA-6vj9-mwq6-2f5v
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
signal_observed_at
2026-09-29T00:57:22+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/nodemailer

AFFECTS (1)

→[Software]npm/nodemailer

HAS_WEAKNESS (1)

→[Weakness]Improper Certificate Validation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6vj9-mwq6-2f5v (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal