Impact
Nodemailer before version 9.1.0 contains a quadratic time complexity flaw in its addressparser module. An attacker can trigger the flaw by submitting a single email with a crafted, comma‑separated address list that causes the parser to consume 100 % of the CPU, freezing the Node.js event loop and rendering the mail server unresponsive. The weakness is a classic denial‑of‑service attack that compromises availability of the affected application.
Affected Systems
All installations of the Nodemailer library with a version prior to 9.1.0 are vulnerable. The flaw is present in any environment that uses Node.js to process email messages through this library; it applies broadly to web applications, microservices, or email relay services that incorporate Nodemailer.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, suggesting high severity. Its EPSS score is below 1 %, indicating a low likelihood of widespread exploitation at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the attack vector is straightforward: a remote attacker sends an email containing a very large list of addresses, triggering the quadratic parse routine and exhausting CPU resources. Because the flaw exploits a public API, no privileged access or local code execution is required.
OpenCVE Enrichment