Impact
Nodemailer versions earlier than 9.1.0 fail to perform the required UTS‑46 normalization when encoding international domain names, which causes the domain resolver to compute a Punycode A‑label that differs from standards‑compliant parsers. This flaw allows an attacker to embed invisible characters or compatibility mappings into a recipient address that passes Nodemailer’s allow‑list checks, yet the underlying SMTP transaction is directed to an attacker‑controlled domain. The result is that an email appears to be sent to a legitimate address but is actually delivered to a hostile domain, enabling spoofing or phishing campaigns. The weakness is an authentication or authorization bypass, identified as CWE‑436.
Affected Systems
The vulnerability exists in the Nodemailer npm package for Node.js. Any installation of Nodemailer older than version 9.1.0 is affected. Systems that rely on these older releases to send outbound email—whether in production, staging, or test environments—are at risk.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. The EPSS score is less than 1 percent, reflecting currently low published exploitation activity, and the flaw is not listed in the CISA KEV catalog. The attack does not require elevated privileges; the likely attack vector is via crafted email addresses supplied to the Nodemailer instance, typically through a web application that sends email. If an attacker can influence the recipient data, they can inject the malformed address and trigger the bypass for domain resolution.
OpenCVE Enrichment