Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. nodemailer
  4. ›
  5. GHSA-wmmp-3585-3rmp

GHSA-wmmp-3585-3rmp: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

September 8, 2026

Nodemailer resolves an international (IDN / non-ASCII) recipient domain to a different Punycode xn-- label than every UTS‑46‑conformant parser (web browsers, the WHATWG URL Standard, Node’s url.domainToASCII, Python’s idna). Its address normalizer (_normalizeAddress in lib/mime-node/index.js) uses the bundled raw RFC‑3492 Punycode codec with no UTS‑46 mapping/normalization, so a domain that a standards‑compliant validator maps to a trusted domain is delivered by Nodemailer to a different, attacker‑registrable domain.

An application that applies a domain allow‑list / same‑domain check to a recipient using a normal IDN‑aware parser (or that shows the normalized recipient to a user for confirmation) and then relies on Nodemailer to deliver to that domain can be induced to send email to an unintended external domain. This is the same weakness class as CVE‑2025‑13033 (Interpretation Conflict, CWE‑436) but reached through IDN/Punycode rather than quoted local‑parts, and it is not addressed by the 7.0.7 fix.

Because the mismatch can be triggered with an invisible character (U+00AD SOFT HYPHEN) that UTS‑46 folds away to the exact trusted domain string, no visible look‑alike/homograph is required.

References

  • github.com/advisories/GHSA-wmmp-3585-3rmp
  • github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148
  • github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e
  • github.com/nodemailer/nodemailer/pull/1848
  • github.com/nodemailer/nodemailer/releases/tag/v9.1.0
  • github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp

Code Behaviors & Features

Detect and mitigate GHSA-wmmp-3585-3rmp with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 9.1.0

Fixed versions

  • 9.1.0

Solution

Upgrade to version 9.1.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation
  • CWE-436: Interpretation Conflict

Source file

npm/nodemailer/GHSA-wmmp-3585-3rmp.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:21:54 +0000.