Inefficient Algorithmic Complexity in nodemailer - #VU153022
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the SMTP client response parser when processing multiline SMTP server replies. A remote attacker can stream continuation lines without a completion line to cause a denial of service.
The issue is reachable during SMTP greeting and EHLO reply processing before client authentication.