CVE-2024-58379
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Summary
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodemailer | nodemailer | 0 < 6.9.9 | affected |
| nodemailer | nodemailer | 6.9.9 | unaffected |
Weaknesses
- CWE-1333: Inefficient Regular Expression Complexity
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-9h6g-pr28-7cqp
- https://www.vulncheck.com/advisories/nodemailer-before-6.9.9-redos-via-attachdataurls-parameter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.