GHSA-8vvx-rff5-p5rq
## Submission metadata | Field | Value | |---|---| | Ecosystem | npm | | Package | `nodemailer` | | Repository | https://github.com/nodemailer/nodemailer | | Tested commit | `40d52215aac65b811d7e131bc916f68605efd9d2` | | Current tested version | `10.0.1` | | Confirmed vulnerable versions | `2.7.2`, `3.0.0`, `7.0.11`, `9.1.1`, `10.0.1` | | Proposed affected range | `>= 2.7.2, <= 10.0.1` | | Patched version | 10.0.2 | ## Summary Nodemailer 10.0.1 does not safely process deeply nested arrays supplied through recipient fields such as `to`, `cc`, and `bcc`. The public `MimeNodeAddressInput` type recursively permits arrays, but `MimeNode._parseAddresses()` flattens only the outermost array. A remaining nested array is passed to `addressparser()`, whose `Tokenizer` coerces the input with `.toString()`. Native `Array.prototype.toString()` recursively processes every nested array through `join()` and `toString()` until the V8 call stack is exhausted. A valid 10,021-byte JSON recipient value containing one address wrapped in 5,000 arrays causes: ```text RangeError: Maximum call stack size exceeded ``` The exception occurs through the normal `sendMail()` API before the `maxRecipients` limit is evaluated. If the integrating application does not catch the synchronous exception around the complete `sendMail()` invocation, the Node.js worker or server process terminates. No SMTP server, remote host, large attachment, or successful email delivery is required. This is distinct from GHSA-rcmh-qjqh-p98v / CVE-2025-14874. The previous vulnerability concerned recursive parsing of RFC 5322 group **strings**. This report uses Nodemailer's structured recipient-array input and never reaches the parser's `MAX_NESTED_GROUP_DEPTH` protection. ## Security impact An attacker who can control a recipient field passed to Nodemailer can trigger stack exhaustion using a roughly 10 KB JSON value. Potentially affected integrations include: - Email-sending HTTP APIs that accept structured re
Properties
- severity
- medium
- summary
- Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
- cvss_score
- 5.9
- retrieved_at
- 2026-09-29T22:26:28+00:00
- ghsa_published
- 2026-09-29T18:23:50Z
- source_url
- https://github.com/advisories/GHSA-8vvx-rff5-p5rq
- ghsa_updated
- 2026-09-29T18:25:05Z
- ghsa_id
- GHSA-8vvx-rff5-p5rq
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-8vvx-rff5-p5rq
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-29T22:18:34+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph