cvssnot scored
how bad it is if exploited, out of 10
epssnot scored
chance of exploitation in the next 30 days
xyz scorenot scored
CyberXYZ composite, out of 10
fig. 01 — GHSA-9h6g-pr28-7cqp, the advisory selected below
// advisories
GHSA-9h6g-pr28-7cqp
UNKNOWNA ReDoS vulnerability occurs when nodemailer tries to parse img files with the parameter attachDataUrls set, causing the stuck of event loop.
- Affected
- >=0, <6.9.9
- Fixed in
- not stated
- Weakness
- CWE-1333
- Published
- 2024-01-31
- Source
- osv
OSV
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.
Checked 2026-09-22 at 01:47 UTC. The most recent advisory here was published 2024-01-31. Updated continuously from NVD, GHSA, OSV and CNA feeds.