Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
Moderate severity
GitHub Reviewed
Published
Dec 18, 2025
to the GitHub Advisory Database
•
Updated Feb 3, 2026
Withdrawn
This advisory was withdrawn on Feb 3, 2026
Description
Published by the National Vulnerability Database
Dec 18, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Reviewed
Dec 18, 2025
Withdrawn
Feb 3, 2026
Last updated
Feb 3, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rcmh-qjqh-p98v. This link is maintained to preserve external references.
Original Description
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
References