Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

GHSA-6VJ9-MWQ6-2F5V: GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer

GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer Vulnerability ID: GHSA-6VJ9-MWQ6-2F5V CVSS Score: 5.9 Published: 2026-09-28 Nodemailer versions 5.0.0 u

GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer

Vulnerability ID: GHSA-6VJ9-MWQ6-2F5V
CVSS Score: 5.9
Published: 2026-09-28

Nodemailer versions 5.0.0 up to 10.0.1 are vulnerable to process-global state contamination inside the DNS caching subsystem. When SMTPS connections are established in a multi-tenant Node.js process targeting a shared gateway, a lower-privilege attacker can seed the global DNS cache with a malicious TLS servername. When a victim subsequently resolves the same gateway host, Nodemailer retrieves the polluted servername, overwrites the victim's connection settings, redirects the TLS session to the attacker's virtual host, and transmits the victim's cleartext SMTP credentials directly to the attacker.

TL;DR

A shared-state vulnerability in Nodemailer's global DNS cache allows attackers to poison connection-specific TLS metadata. This redirects victim SMTPS sessions to an attacker-controlled virtual host, disclosing plaintext SMTP credentials.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-295
  • Attack Vector: Network
  • CVSS: 5.9 (Medium)
  • Impact: High (Cleartext Credential Disclosure)
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications running multi-tenant Nodemailer instances.
  • SaaS platforms employing shared SMTP relay gateways.
  • nodemailer: >= 5.0.0, < 10.0.2 (Fixed in: 10.0.2)

Code Analysis

Commit: a6512db

Fix: do not cache servername in dnsCache

Mitigation Strategies

  • Upgrade Nodemailer dependencies to a secure version (v10.0.2 or later).
  • Bypass DNS caching entirely by specifying IP addresses as the transport host parameter.
  • Isolate tenant execution environments to separate Node.js runtime processes.

Remediation Steps:

  1. Open your application's package configuration file (package.json).
  2. Update the 'nodemailer' dependency specification to '^10.0.2'.
  3. Execute an npm install or yarn install to update the dependency tree.
  4. Verify that SMTPS connections establish properly and inspect outbound SNI logs.

References

Read the full report for GHSA-6VJ9-MWQ6-2F5V on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.