maven package report

Is org.webjars.npm:nodemailer safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 44th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-rcmh-qjqh-p98v, the advisory selected below

      // 1 advisories

      GHSA-rcmh-qjqh-p98v

      HIGHCVE-2025-14874
      // summary

      A DoS can occur that immediately halts the system due to the use of an unsafe function.

      // details

      According to RFC 5322, nested group structures (a group inside another group) are not allowed. Therefore, in lib/addressparser/index.js, the email address parser performs flattening when nested groups appear, since such input is likely to be abnormal. (If the address is valid, it is added as-is.) In other words, the parser flattens all nested groups and inserts them into the final group list. However, the code implemented for this flattening process can be exploited by malicious input and triggers DoS

      RFC 5322 uses a colon (:) to define a group, and commas (,) are used to separate members within a group. At the following location in lib/addressparser/index.js:

      https://github.com/nodemailer/nodemailer/blob/master/lib/addressparser/index.js#L90

      there is code that performs this flattening. The issue occurs when the email address parser attempts to process the following kind of malicious address header:

      Because no recursion depth limit is enforced, the parser repeatedly invokes itself in the pattern
      `addressparser → _handleAddress → addressparser → ...`
      for each nested group. As a result, when an attacker sends a header containing many colons, Nodemailer enters infinite recursion, eventually throwing Maximum call stack size exceeded and causing the process to terminate immediately. Due to the structure of this behavior, no authentication is required, and a single request is enough to shut down the service.
      
      The problematic code section is as follows:

      if (isGroup) { ... if (data.group.length) { let parsedGroup = addressparser(data.group.join(',')); // { if (member.group) { groupMembers = groupMembers.concat(member.group); } else { groupMembers.push(member); } }); } }

      `data.group` is expected to contain members separated by commas, but in the attacker’s payload the group contains colon `(:)` tokens. Because of this, the parser repeatedly triggers recursive calls for each colon, proportional to their number.
      
      ### PoC

      const nodemailer = require('nodemailer');

      function buildDeepGroup(depth) { let parts = []; for (let i = 0; i < depth; i++) { parts.push(g${i}:); } return parts.join(' ') + ' user@example.com;'; }

      const DEPTH = 3000; // { if (err) { console.error('error:', err); } else { console.log('finished :', info && info.envelope); } } );

      As a result, when the colon is repeated beyond a certain threshold, the Node.js process terminates immediately.
      
      ### Impact
      The attacker can achieve the following:
      
      1. Force an immediate crash of any server/service that uses Nodemailer
      2. Kill the backend process with a single web request
      3. In environments using PM2/Forever, trigger a continuous restart loop, causing severe resource exhaustion”
      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      None
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      None
      Integrity
      None
      Availability
      High

      Checked 2026-09-26 at 01:05 UTC. The most recent advisory here was published 2025-12-01. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.