13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether nodemailer is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.4
CVE-2026-82660
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
MEDIUM 5.3
CVE-2024-58379
nodemailer ReDoS when trying to send a specially crafted email
MEDIUM 6.5
CVE-2026-82662
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
MEDIUM 5.4
CVE-2026-82661
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
MEDIUM 4.9
CVE-2026-82853
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
UNKNOWN
CVE-2026-82854
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
HIGH 7.5
CVE-2025-14874
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
HIGH 7.1
GHSA-p6gq-j5cr-w38f
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
HIGH 7.5
GHSA-jj37-3377-m6vv
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
UNKNOWN
CVE-2025-13033
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
MEDIUM 5.3
CVE-2025-14874
Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
MEDIUM 6.3
CVE-2021-23400
Header injection in nodemailer
CRITICAL 9.8
CVE-2020-7769
Command injection in nodemailer
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes