nodemailer is vulnerable to Regular Expression Denial of Service (ReDoS)
50
Medium Risk
The affected versions are vulnerable to regular expression Denial of Service (ReDoS), causing the event loop to become stuck. This occurs when nodemailer attempts to parse image files with the attachDataUrls parameter set or when parsing attachments with embedded files. A specially crafted malicious email can exploit this vulnerability, leading to performance degradation or Denial of Service.
You are affected if you are using a version that falls within the vulnerable range.
nodemailer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 6.9.8.
Upgrade the nodemailer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant