Skip to main content

Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS

0
Medium
Published: 09/29/2026 (09/29/2026, 18:23:50 UTC)
Source: GCVE Database
Product: nodemailer

Description

Nodemailer versions up to 10.0.1 improperly handle deeply nested recipient arrays in fields like to, cc, and bcc. This flaw causes a stack exhaustion denial-of-service (DoS) when processing such inputs, leading to a RangeError and potential termination of the Node.js process. The vulnerability arises because only the outermost array is flattened before passing nested arrays to a parser that converts them to strings recursively, exhausting the V8 call stack. No SMTP server or successful email delivery is required to trigger this. The issue is fixed in version 10.0.2.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

npmghsa
nodemailer
Affected versions
<10.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:21:52 UTC

Technical Analysis

Nodemailer 10.0.1 and earlier versions accept recursively nested arrays for recipient fields (to, cc, bcc) via the MimeNodeAddressInput type. The internal _parseAddresses() method only flattens the outermost array, leaving deeply nested arrays intact. These nested arrays are then passed to addressparser(), which uses a Tokenizer that coerces input to strings via Array.prototype.toString(), recursively joining nested arrays. This recursive stringification exhausts the V8 JavaScript engine call stack, causing a RangeError: Maximum call stack size exceeded. This exception occurs synchronously during the sendMail() API call before recipient limits are checked. If uncaught, the exception terminates the Node.js process handling mail, potentially causing denial of service through repeated malicious inputs. The vulnerability affects versions from 2.7.2 through 10.0.1 and is patched in 10.0.2.

Potential Impact

An attacker able to supply recipient fields with deeply nested arrays can cause a stack exhaustion denial-of-service, crashing the Node.js process running Nodemailer. This can disrupt email sending services, especially those exposing recipient fields to attacker-controlled input without validation or nesting limits. The crash occurs before any network activity or email delivery, so no external dependencies are required. Uncaught exceptions lead to process termination, and repeated exploitation can cause persistent service unavailability due to restart loops.

Mitigation Recommendations

A patch is available in Nodemailer version 10.0.2 that fixes this vulnerability. Users should upgrade to version 10.0.2 or later. Applications should also validate and flatten recipient arrays before passing them to Nodemailer or catch exceptions around the complete sendMail() invocation to prevent process termination. Explicit validation to reject deeply nested recipient arrays can mitigate this issue if upgrading is not immediately possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8vvx-rff5-p5rq
Osv Schema Version
1.4.0
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6abc27cc680226ef6846f8da

Added to database: 09/29/2026, 21:04:12 UTC

Last enriched: 09/29/2026, 21:21:52 UTC

Last updated: 09/30/2026, 03:30:23 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses