---
id: CVE-2024-58379
title: >-
  nodemailer before 6.9.9 contains a regular expression denial of service
  vulnerability in email parsing when attachDataUrls parameter is set or
  processing embedded file attachments
summary: >-
  nodemailer before 6.9.9 contains a regular expression denial of service
  vulnerability in email parsing when attachDataUrls parameter is set or
  processing embedded file attachments. Attackers can send specially crafted
  emails with malicio…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-1333
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:48:28.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58379'
references:
  - url: >-
      https://github.com/nodemailer/nodemailer/security/advisories/GHSA-9h6g-pr28-7cqp
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nodemailer-before-6.9.9-redos-via-attachdataurls-parameter
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58379.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-58379'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2526173'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-58379'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58379'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00304
epssPercentile: 0.20788
ingestedAt: '2026-09-10T15:53:17.038Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - developer_hub
  - enterprise_linux 10
  - self_service_automation_portal 2
---

## Overview

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58379.json)
