{"id":"CVE-2024-58379","title":"nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments","summary":"nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicio…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-1333"],"published":"2026-08-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:48:28.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-58379","references":[{"url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-9h6g-pr28-7cqp","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nodemailer-before-6.9.9-redos-via-attachdataurls-parameter","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58379.json"},{"url":"https://access.redhat.com/security/cve/CVE-2024-58379"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526173"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-58379"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58379"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00304,"epssPercentile":0.23325,"ingestedAt":"2026-09-10T15:53:17.038Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["developer_hub","enterprise_linux 10","self_service_automation_portal 2"],"slug":"CVE-2024-58379","body":"## Overview\n\nnodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · no fix planned: Red Hat Developer Hub, Red Hat Enterprise Linux 10, Self-service automation portal 2 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58379.json)","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}