Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jv2-wqrj-g6x7

Опубликовано: 31 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

EPSS

Процентиль: 9%
0.0019
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

CVSS3: 5.4
redhat
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

CVSS3: 5.4
nvd
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.

CVSS3: 5.4
debian
16 дней назад

Nodemailer before 8.0.9 fails to sanitize carriage return and line fee ...

EPSS

Процентиль: 9%
0.0019
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-93