Inefficient Algorithmic Complexity in nodemailer - #VU153021
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DKIM message parser's header-unfolding loop when DKIM-signing an outbound message with a header folded into many continuation lines. A remote user can supply a large header value to cause a denial of service.
DKIM signing must be enabled.