Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
Nodemailer versions up to 10.0.1 improperly handle deeply nested recipient arrays in fields like to, cc, and bcc. This flaw causes a stack exhaustion denial-of-service (DoS) when processing such inputs, leading to a RangeError and potential termination of the Node.js process. The vulnerability arises because only the outermost array is flattened before passing nested arrays to a parser that converts them to strings recursively, exhausting the V8 call stack. No SMTP server or successful email delivery is required to trigger this. The issue is fixed in version 10.0.2.
AI Analysis
Technical Summary
Nodemailer 10.0.1 and earlier versions accept recursively nested arrays for recipient fields (to, cc, bcc) via the MimeNodeAddressInput type. The internal _parseAddresses() method only flattens the outermost array, leaving deeply nested arrays intact. These nested arrays are then passed to addressparser(), which uses a Tokenizer that coerces input to strings via Array.prototype.toString(), recursively joining nested arrays. This recursive stringification exhausts the V8 JavaScript engine call stack, causing a RangeError: Maximum call stack size exceeded. This exception occurs synchronously during the sendMail() API call before recipient limits are checked. If uncaught, the exception terminates the Node.js process handling mail, potentially causing denial of service through repeated malicious inputs. The vulnerability affects versions from 2.7.2 through 10.0.1 and is patched in 10.0.2.
Potential Impact
An attacker able to supply recipient fields with deeply nested arrays can cause a stack exhaustion denial-of-service, crashing the Node.js process running Nodemailer. This can disrupt email sending services, especially those exposing recipient fields to attacker-controlled input without validation or nesting limits. The crash occurs before any network activity or email delivery, so no external dependencies are required. Uncaught exceptions lead to process termination, and repeated exploitation can cause persistent service unavailability due to restart loops.
Mitigation Recommendations
A patch is available in Nodemailer version 10.0.2 that fixes this vulnerability. Users should upgrade to version 10.0.2 or later. Applications should also validate and flatten recipient arrays before passing them to Nodemailer or catch exceptions around the complete sendMail() invocation to prevent process termination. Explicit validation to reject deeply nested recipient arrays can mitigate this issue if upgrading is not immediately possible.
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
Description
Nodemailer versions up to 10.0.1 improperly handle deeply nested recipient arrays in fields like to, cc, and bcc. This flaw causes a stack exhaustion denial-of-service (DoS) when processing such inputs, leading to a RangeError and potential termination of the Node.js process. The vulnerability arises because only the outermost array is flattened before passing nested arrays to a parser that converts them to strings recursively, exhausting the V8 call stack. No SMTP server or successful email delivery is required to trigger this. The issue is fixed in version 10.0.2.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Nodemailer 10.0.1 and earlier versions accept recursively nested arrays for recipient fields (to, cc, bcc) via the MimeNodeAddressInput type. The internal _parseAddresses() method only flattens the outermost array, leaving deeply nested arrays intact. These nested arrays are then passed to addressparser(), which uses a Tokenizer that coerces input to strings via Array.prototype.toString(), recursively joining nested arrays. This recursive stringification exhausts the V8 JavaScript engine call stack, causing a RangeError: Maximum call stack size exceeded. This exception occurs synchronously during the sendMail() API call before recipient limits are checked. If uncaught, the exception terminates the Node.js process handling mail, potentially causing denial of service through repeated malicious inputs. The vulnerability affects versions from 2.7.2 through 10.0.1 and is patched in 10.0.2.
Potential Impact
An attacker able to supply recipient fields with deeply nested arrays can cause a stack exhaustion denial-of-service, crashing the Node.js process running Nodemailer. This can disrupt email sending services, especially those exposing recipient fields to attacker-controlled input without validation or nesting limits. The crash occurs before any network activity or email delivery, so no external dependencies are required. Uncaught exceptions lead to process termination, and repeated exploitation can cause persistent service unavailability due to restart loops.
Mitigation Recommendations
A patch is available in Nodemailer version 10.0.2 that fixes this vulnerability. Users should upgrade to version 10.0.2 or later. Applications should also validate and flatten recipient arrays before passing them to Nodemailer or catch exceptions around the complete sendMail() invocation to prevent process termination. Explicit validation to reject deeply nested recipient arrays can mitigate this issue if upgrading is not immediately possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8vvx-rff5-p5rq
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6abc27cc680226ef6846f8da
Added to database: 09/29/2026, 21:04:12 UTC
Last enriched: 09/29/2026, 21:21:52 UTC
Last updated: 09/30/2026, 03:30:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.