Information on source package node-nodemailer

Available versions

ReleaseVersion
bookworm6.8.0+~6.4.6-1
trixie6.10.0+~6.4.17-1+deb13u1
forky10.0.10+~8.0.1-1
sid10.0.10+~8.0.2-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-100702vulnerablevulnerable (no DSA)fixedfixedNodemailer before 10.0.2 fails to properly flatten deeply nested array ...
CVE-2026-100701vulnerablevulnerable (no DSA)fixedfixedNodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cach ...
CVE-2026-100700vulnerablevulnerable (no DSA)fixedfixednodemailer before 10.0.6 contains a denial of service vulnerability in ...
CVE-2026-100699vulnerablevulnerable (no DSA)fixedfixedNodemailer is a Node.js email-sending library. In versions >= 9.1.0 an ...
CVE-2026-92598vulnerablevulnerable (no DSA)fixedfixedNodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ...
CVE-2026-92597vulnerablevulnerable (no DSA)fixedfixedNodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments ...
CVE-2026-92596vulnerablevulnerable (no DSA)fixedfixedNodemailer before 9.1.0 contains a quadratic time complexity vulnerabi ...
CVE-2026-92595vulnerablevulnerable (no DSA)fixedfixedNodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ...
CVE-2026-90776vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ...
CVE-2026-82854vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.4 is vulnerable to SMTP command injection throug ...
CVE-2026-82853vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer versions before 8.0.5 contain an SMTP command injection vul ...
CVE-2026-82662vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.8 disables TLS certificate verification in lib/f ...
CVE-2026-82661vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.9 fails to sanitize carriage return and line fee ...
CVE-2026-82660vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedNodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...
CVE-2026-82659vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixednodemailer before 9.0.1 fails to apply disableFileAccess and disableUr ...
CVE-2025-14874vulnerable (no DSA)vulnerable (no DSA)fixedfixedA flaw was found in Nodemailer. This vulnerability allows a denial of ...
CVE-2025-13033vulnerable (no DSA)fixedfixedfixedA vulnerability was identified in the email parsing library due to imp ...
CVE-2024-58379vulnerable (no DSA, postponed)fixedfixedfixednodemailer before 6.9.9 contains a regular expression denial of servic ...

Resolved issues

BugDescription
CVE-2021-23400The package nodemailer before 6.6.1 are vulnerable to HTTP Header Inje ...
CVE-2020-7769This affects the package nodemailer before 6.4.16. Use of crafted reci ...

Search for package or bug name: Reporting problems