Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
### Summary Nodemailer's process-global DNS cache is keyed only by `host`, but each cache entry also stores the caller-specific TLS `servername`. When two direct SMTPS transports use the same DNS host with different `tls.servername` values, the first transport's server name is returned to the second transport and overwrites its explicitly configured value. As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with `rejectUnauthorized: true`, and sends the victim's SMTP credentials to it. ## Affected component - **Ecosystem:** npm - **Package:** `nodemailer` - **Repository:** https://github.com/nodemailer/nodemailer - **Tested version:** `10.0.1` - **Tested commit:** `40d52215aac65b811d7e131bc916f68605efd9d2` - **Runtime-confirmed vulnerable versions:** `5.0.0` and `10.0.1` - **Affected versions:** `>= 5.0.0, <= 10.0.1` - **Patched versions:** None known at the time of this report - **Affected mode:** Direct TLS/SMTPS connections (`secure: true`) where different transports use the same non-IP `host` and different TLS `servername` values The vulnerable cache implementation was introduced in commit `6859b5dd96c8d9f0070a3169a877181b71df4a3b` on 2018-12-28. Git history shows `v5.0.0` as the first release tag containing that commit. The behavior remains present in `v10.0.1`. ## Details ### Root cause `src/shared/index.ts` defines one module-global DNS cache, keyed only by the DNS host: ```ts export const dnsCache = new Map<string, DnsCacheEntry>(); ``` Although the cache key contains only `host`, the cached value contains both DNS addresses and the request-specific TLS identity: ```ts const value: DnsCacheValue = { addresses: allAddresses, servername: options.servername || host }; dnsCache.set(host, { value, expires: Date.now() + (options.dnsTtl || DNS_TTL) }); ``` On a cache hit, `resolveHostname()` returns the cached `servername` without considering the current call's `options.servername`: ```ts if (!cached.expires || cached.expires >= now) { return callback( null, formatDNSValue(cached.value, { cached: true }) ); } ``` `formatDNSValue()` copies that stale value into the result: ```ts return Object.assign( { servername: value.servername, host, _addresses: addresses }, extra || {} ); ``` For a direct TLS connection, `SMTPConnection.connect()` initially copies the current transport's TLS configuration into `opts`. `_resolveAndConnect()` then overwrites every truthy field with the cached resolver result, including `opts.servername`: ```ts Object.assign(opts, this.options.tls || {}); if (this.servername && !opts.servername) { opts.servername = this.servername; } return this._resolveAndConnect(opts, resolved => { this._connectToHost(opts, this.secureConnection); }); ``` ```ts for (const key of Object.keys(resolved!)) { if (key.charAt(0) !== '_' && (resolved as { [key: string]: any })[key]) { (opts as { [key: string]: any })[key] = (resolved as { [key: string]: any })[key]; } } ``` The resulting `opts` object is passed to `tls.connect()`. Node therefore sends the cached server name as SNI and verifies the certificate against that cached name, rather than against the server name explicitly configured for the current transport. The default DNS cache TTL is five minutes: ```ts const DNS_TTL = 5 * 60 * 1000; ``` ### Code path ```text Tenant A: createTransport({ host: H, secure: true, tls: { servername: attackerName } }) -> SMTPConnection.connect() -> _resolveAndConnect(opts) -> shared.resolveHostname({ host: H, servername: attackerName }) -> dnsCache.set(H, { addresses, servername: attackerName }) Victim: createTransport({ host: H, secure: true, tls: { servername: victimName } }) -> SMTPConnection.connect() -> opts.servername = victimName -> _resolveAndConnect(opts) -> shared.resolveHostname({ host: H, servername: victimName }) -> dnsCache.get(H) -> returns cached servername = attackerName -> _resolveAndConnect overwrites opts.servername -> tls.connect({ servername: attackerName }) -> attacker SNI virtual host and certificate are selected -> AUTH transmits victim SMTP credentials ``` ### Relevant source locations in the tested revision - `src/shared/index.ts:184` — five-minute default cache TTL - `src/shared/index.ts:245` — process-global cache keyed by host - `src/shared/index.ts:247-262` — cached `servername` returned by `formatDNSValue()` - `src/shared/index.ts:292-323` — host-only lookup and cache-hit return - `src/shared/index.ts:350-359` — caller-specific `servername` stored in host-only cache - `src/smtp-connection/index.ts:713-729` — direct
Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
Description
### Summary Nodemailer's process-global DNS cache is keyed only by `host`, but each cache entry also stores the caller-specific TLS `servername`. When two direct SMTPS transports use the same DNS host with different `tls.servername` values, the first transport's server name is returned to the second transport and overwrites its explicitly configured value. As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with `rejectUnauthorized: true`, and sends the victim's SMTP credentials to it. ## Affected component - **Ecosystem:** npm - **Package:** `nodemailer` - **Repository:** https://github.com/nodemailer/nodemailer - **Tested version:** `10.0.1` - **Tested commit:** `40d52215aac65b811d7e131bc916f68605efd9d2` - **Runtime-confirmed vulnerable versions:** `5.0.0` and `10.0.1` - **Affected versions:** `>= 5.0.0, <= 10.0.1` - **Patched versions:** None known at the time of this report - **Affected mode:** Direct TLS/SMTPS connections (`secure: true`) where different transports use the same non-IP `host` and different TLS `servername` values The vulnerable cache implementation was introduced in commit `6859b5dd96c8d9f0070a3169a877181b71df4a3b` on 2018-12-28. Git history shows `v5.0.0` as the first release tag containing that commit. The behavior remains present in `v10.0.1`. ## Details ### Root cause `src/shared/index.ts` defines one module-global DNS cache, keyed only by the DNS host: ```ts export const dnsCache = new Map<string, DnsCacheEntry>(); ``` Although the cache key contains only `host`, the cached value contains both DNS addresses and the request-specific TLS identity: ```ts const value: DnsCacheValue = { addresses: allAddresses, servername: options.servername || host }; dnsCache.set(host, { value, expires: Date.now() + (options.dnsTtl || DNS_TTL) }); ``` On a cache hit, `resolveHostname()` returns the cached `servername` without considering the current call's `options.servername`: ```ts if (!cached.expires || cached.expires >= now) { return callback( null, formatDNSValue(cached.value, { cached: true }) ); } ``` `formatDNSValue()` copies that stale value into the result: ```ts return Object.assign( { servername: value.servername, host, _addresses: addresses }, extra || {} ); ``` For a direct TLS connection, `SMTPConnection.connect()` initially copies the current transport's TLS configuration into `opts`. `_resolveAndConnect()` then overwrites every truthy field with the cached resolver result, including `opts.servername`: ```ts Object.assign(opts, this.options.tls || {}); if (this.servername && !opts.servername) { opts.servername = this.servername; } return this._resolveAndConnect(opts, resolved => { this._connectToHost(opts, this.secureConnection); }); ``` ```ts for (const key of Object.keys(resolved!)) { if (key.charAt(0) !== '_' && (resolved as { [key: string]: any })[key]) { (opts as { [key: string]: any })[key] = (resolved as { [key: string]: any })[key]; } } ``` The resulting `opts` object is passed to `tls.connect()`. Node therefore sends the cached server name as SNI and verifies the certificate against that cached name, rather than against the server name explicitly configured for the current transport. The default DNS cache TTL is five minutes: ```ts const DNS_TTL = 5 * 60 * 1000; ``` ### Code path ```text Tenant A: createTransport({ host: H, secure: true, tls: { servername: attackerName } }) -> SMTPConnection.connect() -> _resolveAndConnect(opts) -> shared.resolveHostname({ host: H, servername: attackerName }) -> dnsCache.set(H, { addresses, servername: attackerName }) Victim: createTransport({ host: H, secure: true, tls: { servername: victimName } }) -> SMTPConnection.connect() -> opts.servername = victimName -> _resolveAndConnect(opts) -> shared.resolveHostname({ host: H, servername: victimName }) -> dnsCache.get(H) -> returns cached servername = attackerName -> _resolveAndConnect overwrites opts.servername -> tls.connect({ servername: attackerName }) -> attacker SNI virtual host and certificate are selected -> AUTH transmits victim SMTP credentials ``` ### Relevant source locations in the tested revision - `src/shared/index.ts:184` — five-minute default cache TTL - `src/shared/index.ts:245` — process-global cache keyed by host - `src/shared/index.ts:247-262` — cached `servername` returned by `formatDNSValue()` - `src/shared/index.ts:292-323` — host-only lookup and cache-hit return - `src/shared/index.ts:350-359` — caller-specific `servername` stored in host-only cache - `src/smtp-connection/index.ts:713-729` — direct
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6vj9-mwq6-2f5v
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6abb4187f7a7c54106cc2f90
Added to database: 09/29/2026, 04:41:43 UTC
Last updated: 09/29/2026, 04:41:43 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.