GHSA-G57G-F23G-4646: GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser
GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser Vulnerability ID: GHSA-G57G-F23G-4646 CVSS Score: 6.5 Published: 2026-09-29 Nodemailer versions prior to 10.0.9 are vulnerable
GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser
Vulnerability ID: GHSA-G57G-F23G-4646
CVSS Score: 6.5
Published: 2026-09-29
Nodemailer versions prior to 10.0.9 are vulnerable to a parser differential bug. When processing a quoted local-part followed by an RFC 5322 comment and trailing characters, the internal addressparser module fails to order its normalization routine correctly. This error results in the generation of malformed envelope recipient addresses containing injected whitespace and secondary domains, allowing attackers to bypass routing restrictions and exfiltrate sensitive emails.
TL;DR
A parser logic flaw in Nodemailer allows attackers to inject secondary domains and spaces into email envelopes, leading to routing bypasses and email interception.
β οΈ Exploit Status: POC
Technical Details
- Vulnerability Type: Parser Differential / SMTP Parameter Injection
- CWE ID: CWE-20
- Attack Vector: Network / Input-driven
- Affected Component: src/addressparser/index.ts
- Exploit Status: Proof of Concept
- Remediation Status: Official Patch Available (v10.0.9)
Affected Systems
- Node.js applications using Nodemailer for SMTP transport
- Upstream systems relying on domain-level email whitelisting
-
nodemailer: < 10.0.9 (Fixed in:
10.0.9)
Code Analysis
Commit: 2f36eb1
Fix address parsing logic regarding quoted local-parts and comments
Exploit Details
- GitHub Security Advisory: Advisory and test-case proof-of-concepts detailing the vulnerable inputs
Mitigation Strategies
- Upgrade Nodemailer to version 10.0.9 or higher
- Implement strict upstream validation filtering out parenthesis and quotes in user email submissions
- Configure the Mail Transfer Agent (MTA) to reject SMTP envelopes containing whitespace or malformed recipient fields
Remediation Steps:
- Run npm install [email protected] to update the package
- Verify the dependency tree using npm list nodemailer
- Deploy upstream input validation filters as a defense-in-depth measure
References
Read the full report for GHSA-G57G-F23G-4646 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.