GHSA-6vj9-mwq6-2f5v
### Summary Nodemailer's process-global DNS cache is keyed only by `host`, but each cache entry also stores the caller-specific TLS `servername`. When two direct SMTPS transports use the same DNS host with different `tls.servername` values, the first transport's server name is returned to the second transport and overwrites its explicitly configured value. As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with `rejectUnauthorized: true`, and sends the victim's SMTP credentials to it. ## Affected component - **Ecosystem:** npm - **Package:** `nodemailer` - **Repository:** https://github.com/nodemailer/nodemailer - **Tested version:** `10.0.1` - **Tested commit:** `40d52215aac65b811d7e131bc916f68605efd9d2` - **Runtime-confirmed vulnerable versions:** `5.0.0` and `10.0.1` - **Affected versions:** `>= 5.0.0, <= 10.0.1` - **Patched versions:** None known at the time of this report - **Affected mode:** Direct TLS/SMTPS connections (`secure: true`) where different transports use the same non-IP `host` and different TLS `servername` values The vulnerable cache implementation was introduced in commit `6859b5dd96c8d9f0070a3169a877181b71df4a3b` on 2018-12-28. Git history shows `v5.0.0` as the first release tag containing that commit. The behavior remains present in `v10.0.1`. ## Details ### Root cause `src/shared/index.ts` defines one module-global DNS cache, keyed only by the DNS host: ```ts export const dnsCache = new Map<string, DnsCacheEntry>(); ``` Although the cache key contains only `host`, the cached value contains both DNS addresses and the request-specific TLS identity: ```ts const value: DnsCacheValue = { addresses: allAddresses, servername: options.servername || host }; dnsCache.set(host, { v
Properties
- severity
- medium
- summary
- Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
- cvss_score
- 5.9
- retrieved_at
- 2026-09-29T00:57:22+00:00
- ghsa_published
- 2026-09-28T21:56:05Z
- source_url
- https://github.com/advisories/GHSA-6vj9-mwq6-2f5v
- ghsa_updated
- 2026-09-28T21:57:00Z
- ghsa_id
- GHSA-6vj9-mwq6-2f5v
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-6vj9-mwq6-2f5v
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
- signal_observed_at
- 2026-09-29T00:57:22+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph