Impact
Nodemailer versions 9.1. a quadratic time‑complexity bug in the addressparser component. When parsing email headers that include RFC 5322 comments, the algorithm performs excessive computation (CWE‑407), consuming large amounts of CPU and temporarily blocking the Node.js event loop. This results in a denial‑of‑service condition for applications that rely on Nodemailer to send or parse mail.
Affected Systems
The vulnerability affects the Nodemailer library distributed via npm. Any deployment that uses Nodemailer versions 9.1.0, 9.2.x, 9.3.x, 10.0.4 is impacted; upgrading flaw.
Risk and Exploitability
The CVSS score of 8.7 classifies this vulnerability as high severity, while the EPSS score of < 1% indicates a very low probability of exploitation; it is not listed in CISA KEV. An attacker can exploit the weakness simply by sending a crafted email containing comment‑separated atoms to a system that parses addresses with Nodemailer. The attack can block the event loop for several seconds, disrupting service availability.
OpenCVE Enrichment