Intel

AIKIDO-2026-284931

nodemailer is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-39m8-27wv-hr27 Published 2 days ago

65

Medium Risk

This Affects:

JSnodemailer
0.0.1 - 10.0.9
Fixed in 10.0.10
Are you affected? Scan for Free

TL;DR

Nodemailer's DKIM message parser unfolds RFC 5322 header continuation lines by repeatedly concatenating each new line onto the previous line and re-testing a continuation regex against the growing merged string. Signing a message whose header folds into many continuation lines, most commonly a large recipient list, drives this re-scan into O(n^2) CPU and blocks the single threaded Node.js event loop for several seconds. The cost scales with how many continuation lines the signed header folds into, so a user controlled recipient list or custom header can trigger it. The fix unfolds headers in a single forward pass that tests each freshly split line only once.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you DKIM-sign outbound messages whose headers can fold into many continuation lines, such as a large recipient list.

Background info

nodemailer is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.9.

How to fix this

Upgrade the nodemailer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform