Impact
Nodemailer mis‑parses RFC 5322 comments in email addresses, allowing a crafted address such as user@good‑corp.com(x)evil.com to be interpreted as the single domain good‑corp.comevil.com, which an attacker can register. The library then uses this domain for both the SMTP envelope and email headers, leading to delivery of mail to an attacker‑controlled zone. This can facilitate phishing, spoofing, and spam without explaining the undesired domain to the user. The flaw corresponds to both CWE‑436 (Failure to Clarify Domain) and CWE‑1286 (Improper Handling of Comments).
Affected Systems
The vulnerability affects Nodemailer library versions from 6.9.16 through 9.0.9 inclusive. The fix is delivered in Nodemailer 9.1.0 and later. No other products or platforms are listed.
Risk and Exploitability
With a CVSS score of 8.3, the issue is considered high severity. EPSS indicates a very low current exploitation probability (<1%), and the vulnerability is not in the CISA KEV catalog. An attacker can exploit it by submitting a maliciously crafted recipient address to any application that uses Nodemailer and performs weak or no domain validation, usually without elevated privileges. The attack would result in mail being routed to the attacker’s domain and may bypass normal spam controls. The flaw involves both improper domain clarification (CWE‑436) and improper handling of comments (CWE‑1286).
OpenCVE Enrichment