npm

nodemailer

View on npm registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether nodemailer is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
npm

CVE-2026-92596

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

MEDIUM 6.5
npm

CVE-2026-92597

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

MEDIUM 5.9
npm

CVE-2026-92595

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

MEDIUM 6.5
npm

CVE-2026-92598

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

HIGH 7.1
npm

GHSA-h3hj-cmcx-xc66

Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

HIGH 7.1
npm

CVE-2026-82659

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

MEDIUM 5.4
npm

CVE-2026-82661

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

MEDIUM 4.9
npm

CVE-2026-82853

Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

HIGH 7.5
npm

CVE-2025-14874

Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls

MEDIUM 5.4
npm

CVE-2026-82660

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

MEDIUM 6.5
npm

CVE-2026-82662

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

UNKNOWN
npm

CVE-2026-82854

Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter

MEDIUM 5.3
npm

GHSA-46j5-6fg5-4gv3

Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion

UNKNOWN
npm

CVE-2025-13033

Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict

MEDIUM 5.3
npm

CVE-2024-58379

nodemailer ReDoS when trying to send a specially crafted email

HIGH 7.5
npm

GHSA-jj37-3377-m6vv

Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict

MEDIUM 6.3
npm

CVE-2021-23400

Header injection in nodemailer

CRITICAL 9.8
npm

CVE-2020-7769

Command injection in nodemailer

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes