Intel

AIKIDO-2026-810392

nodemailer is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-4g23-2xm8-66gc Published 2 days ago

59

Medium Risk

This Affects:

JSnodemailer
3.0.0 - 10.0.9
Fixed in 10.0.10
Are you affected? Scan for Free

TL;DR

Nodemailer's SMTP client builds a multiline server reply by appending each continuation line to a single queued string and rescanning that whole string with lastIndexOf and slice on every new line. The string grows with each line, so the rescan cost grows with the accumulated reply and CPU time becomes quadratic. A malicious or on path SMTP server that streams continuation lines without ever completing the reply blocks the Node.js event loop before the client authenticates. The fix tracks partial reply state separately so each line is checked once and caps the buffered reply size.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you connect to an SMTP server that is untrusted or reachable by an on path network party.

Background info

nodemailer is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 10.0.9.

How to fix this

Upgrade the nodemailer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform