Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14874

Опубликовано: 18 дек. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-nodemailerunfixedpackage
node-nodemailerno-dsatrixiepackage
node-nodemailerno-dsabookwormpackage
node-nodemailerpostponedbullseyepackage

Примечания

  • https://github.com/nodemailer/nodemailer/security/advisories/GHSA-rcmh-qjqh-p98v

  • Fixed by: https://github.com/nodemailer/nodemailer/commit/b61b9c0cfd682b6f647754ca338373b68336a150 (v7.0.11)

EPSS

Процентиль: 17%
0.00054
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

CVSS3: 5.3
github
около 2 месяцев назад

Nodemailer is vulnerable to DoS through Uncontrolled Recursion

EPSS

Процентиль: 17%
0.00054
Низкий