18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether nodemailer is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-92596
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
MEDIUM 6.5
CVE-2026-92597
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
MEDIUM 5.9
CVE-2026-92595
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
MEDIUM 6.5
CVE-2026-92598
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
HIGH 7.1
GHSA-h3hj-cmcx-xc66
Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
HIGH 7.1
CVE-2026-82659
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
MEDIUM 5.4
CVE-2026-82661
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
MEDIUM 4.9
CVE-2026-82853
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
HIGH 7.5
CVE-2025-14874
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
MEDIUM 5.4
CVE-2026-82660
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
MEDIUM 6.5
CVE-2026-82662
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
UNKNOWN
CVE-2026-82854
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
MEDIUM 5.3
GHSA-46j5-6fg5-4gv3
Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
UNKNOWN
CVE-2025-13033
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
MEDIUM 5.3
CVE-2024-58379
nodemailer ReDoS when trying to send a specially crafted email
HIGH 7.5
GHSA-jj37-3377-m6vv
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
MEDIUM 6.3
CVE-2021-23400
Header injection in nodemailer
CRITICAL 9.8
CVE-2020-7769
Command injection in nodemailer
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes