nodemailer is vulnerable to Denial of Service (DoS)
59
Medium Risk
Nodemailer's SMTP client builds a multiline server reply by appending each continuation line to a single queued string and rescanning that whole string with lastIndexOf and slice on every new line. The string grows with each line, so the rescan cost grows with the accumulated reply and CPU time becomes quadratic. A malicious or on path SMTP server that streams continuation lines without ever completing the reply blocks the Node.js event loop before the client authenticates. The fix tracks partial reply state separately so each line is checked once and caps the buffered reply size.
You are affected if you are using a version that falls within the vulnerable range and you connect to an SMTP server that is untrusted or reachable by an on path network party.
nodemailer is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 10.0.9.
Upgrade the nodemailer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.