nodemailer
15 known vulnerabilities · 0 critical · 3 high
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Malicious code in noirxnodemailer (npm)