Information on source package node-nodemailer

Available versions

ReleaseVersion
bookworm6.8.0+~6.4.6-1
trixie6.10.0+~6.4.17-1+deb13u1
forky10.0.0+~8.0.1-1
sid10.0.10+~8.0.1-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-90776vulnerablevulnerable (no DSA)vulnerablefixedNodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ...
CVE-2026-82854vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.4 is vulnerable to SMTP command injection throug ...
CVE-2026-82853vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer versions before 8.0.5 contain an SMTP command injection vul ...
CVE-2026-82662vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.8 disables TLS certificate verification in lib/f ...
CVE-2026-82661vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.9 fails to sanitize carriage return and line fee ...
CVE-2026-82660vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...
CVE-2026-82659vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixednodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...
CVE-2025-14874vulnerable (no DSA)vulnerable (no DSA)fixedfixedA flaw was found in Nodemailer. This vulnerability allows a denial of ...
CVE-2025-13033vulnerable (no DSA)fixedfixedfixedA vulnerability was identified in the email parsing library due to imp ...
CVE-2024-58379vulnerable (no DSA, postponed)fixedfixedfixednodemailer before 6.9.9 contains a regular expression denial of servic ...

Resolved issues

BugDescription
CVE-2021-23400The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...
CVE-2020-7769This affects the package nodemailer before 6.4.16. Use of crafted reci ...

Search for package or bug name: Reporting problems