A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
2025-12-18T09:15:44.870
2026-01-08T03:15:43.190
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nodemailer | nodemailer | < 7.0.11 | Yes |
| Application | redhat | advanced_cluster_management_for_kubernetes | 2.0 | Yes |
| Application | redhat | ceph_storage | 8.0 | Yes |
| Application | redhat | developer_hub | - | Yes |