GHSA-5hcf-56h7-4fvxHighCVSS 5.9

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process.

🔗 References (4)