mediumCVSS 5.9Vulnerability

GHSA-8vvx-rff5-p5rq

## Submission metadata | Field | Value | |---|---| | Ecosystem | npm | | Package | `nodemailer` | | Repository | https://github.com/nodemailer/nodemailer | | Tested commit | `40d52215aac65b811d7e131bc916f68605efd9d2` | | Current tested version | `10.0.1` | | Confirmed vulnerable versions | `2.7.2`, `3.0.0`, `7.0.11`, `9.1.1`, `10.0.1` | | Proposed affected range | `>= 2.7.2, <= 10.0.1` | | Patched version | 10.0.2 | ## Summary Nodemailer 10.0.1 does not safely process deeply nested arrays supplied through recipient fields such as `to`, `cc`, and `bcc`. The public `MimeNodeAddressInput` type recursively permits arrays, but `MimeNode._parseAddresses()` flattens only the outermost array. A remaining nested array is passed to `addressparser()`, whose `Tokenizer` coerces the input with `.toString()`. Native `Array.prototype.toString()` recursively processes every nested array through `join()` and `toString()` until the V8 call stack is exhausted. A valid 10,021-byte JSON recipient value containing one address wrapped in 5,000 arrays causes: ```text RangeError: Maximum call stack size exceeded ``` The exception occurs through the normal `sendMail()` API before the `maxRecipients` limit is evaluated. If the integrating application does not catch the synchronous exception around the complete `sendMail()` invocation, the Node.js worker or server process terminates. No SMTP server, remote host, large attachment, or successful email delivery is required. This is distinct from GHSA-rcmh-qjqh-p98v / CVE-2025-14874. The previous vulnerability concerned recursive parsing of RFC 5322 group **strings**. This report uses Nodemailer's structured recipient-array input and never reaches the parser's `MAX_NESTED_GROUP_DEPTH` protection. ## Security impact An attacker who can control a recipient field passed to Nodemailer can trigger stack exhaustion using a roughly 10 KB JSON value. Potentially affected integrations include: - Email-sending HTTP APIs that accept structured re

Properties

severity
medium
summary
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
cvss_score
5.9
retrieved_at
2026-09-29T22:26:28+00:00
ghsa_published
2026-09-29T18:23:50Z
source_url
https://github.com/advisories/GHSA-8vvx-rff5-p5rq
ghsa_updated
2026-09-29T18:25:05Z
ghsa_id
GHSA-8vvx-rff5-p5rq
last_source
GitHub Advisory Database
cve_id
GHSA-8vvx-rff5-p5rq
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-29T22:18:34+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/nodemailer

AFFECTS (1)

→[Software]npm/nodemailer

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Recursion

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8vvx-rff5-p5rq (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal