CVE-2025-14874High· 7.5▾ TwilightA flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
nodemailer < 7.0.11advanced_cluster_management_for_kubernetes = 2.0ceph_storage = 8.0developer_hubUpgrade past the affected range:
nodemailer 7.0.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90776High· 7.5Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments
GHSA-prgh-xp8r-p3m5High· 7.5Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
GHSA-g57g-f23g-4646Medium· 5.3Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
GHSA-v53p-9fqp-m79jHigh· 7.5Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
GHSA-8vvx-rff5-p5rqMedium· 5.9Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
GHSA-6vj9-mwq6-2f5vMedium· 5.9Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure