nodemailer is vulnerable to Denial of Service (DoS)
65
Medium Risk
Nodemailer's DKIM message parser unfolds RFC 5322 header continuation lines by repeatedly concatenating each new line onto the previous line and re-testing a continuation regex against the growing merged string. Signing a message whose header folds into many continuation lines, most commonly a large recipient list, drives this re-scan into O(n^2) CPU and blocks the single threaded Node.js event loop for several seconds. The cost scales with how many continuation lines the signed header folds into, so a user controlled recipient list or custom header can trigger it. The fix unfolds headers in a single forward pass that tests each freshly split line only once.
You are affected if you are using a version that falls within the vulnerable range and you DKIM-sign outbound messages whose headers can fold into many continuation lines, such as a large recipient list.
nodemailer is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.9.
Upgrade the nodemailer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.