Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. nodemailer
  4. ›
  5. GHSA-6vj9-mwq6-2f5v

GHSA-6vj9-mwq6-2f5v: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure

September 28, 2026

Nodemailer’s process-global DNS cache is keyed only by host, but each cache entry also stores the caller-specific TLS servername. When two direct SMTPS transports use the same DNS host with different tls.servername values, the first transport’s server name is returned to the second transport and overwrites its explicitly configured value.

As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker’s TLS virtual host, accepts the attacker’s certificate with rejectUnauthorized: true, and sends the victim’s SMTP credentials to it.

References

  • github.com/advisories/GHSA-6vj9-mwq6-2f5v
  • github.com/nodemailer/nodemailer/commit/a6512dbcb3c6e7f2f70d3acccc5752defe3c61fe
  • github.com/nodemailer/nodemailer/releases/tag/v10.0.2
  • github.com/nodemailer/nodemailer/security/advisories/GHSA-6vj9-mwq6-2f5v

Code Behaviors & Features

Detect and mitigate GHSA-6vj9-mwq6-2f5v with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.0.0 before 10.0.2

Fixed versions

  • 10.0.2

Solution

Upgrade to version 10.0.2 or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-295: Improper Certificate Validation

Source file

npm/nodemailer/GHSA-6vj9-mwq6-2f5v.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 29 Sep 2026 12:18:05 +0000.