GHSA-6vj9-mwq6-2f5v: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
Nodemailer’s process-global DNS cache is keyed only by host, but each cache entry also stores the caller-specific TLS servername. When two direct SMTPS transports use the same DNS host with different tls.servername values, the first transport’s server name is returned to the second transport and overwrites its explicitly configured value.
As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker’s TLS virtual host, accepts the attacker’s certificate with rejectUnauthorized: true, and sends the victim’s SMTP credentials to it.
References
Code Behaviors & Features
Detect and mitigate GHSA-6vj9-mwq6-2f5v with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →