Regular Expression Denial of Service in Nodemailer by Nodemailer
CVE-2024-58379

6.9MEDIUM

Key Information:

Vendor

Nodemailer

Vendor
CVE Published:
31 August 2026

What is CVE-2024-58379?

Nodemailer versions prior to 6.9.9 are susceptible to a regular expression denial of service vulnerability, affecting email parsing when the attachDataUrls parameter is enabled or during the processing of embedded file attachments. By sending specially crafted emails with malicious data URLs or embedded attachments, attackers can exploit this flaw to induce the event loop to become unresponsive, resulting in service disruption.

Affected Version(s)

nodemailer 0 < 6.9.9

nodemailer 6.9.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

francoatmega
.