Nodemailer: nodemailer: denial of service via crafted email address header
Published Dec 18, 2025
7.5
HIGHCVSS 3.1
EPSS 0.56%
Description
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
Affected products
-
-
-
-
- Version 0StatusaffectedConstraints<7.0.11
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | affected |
| ||||||
| Red Hat | Red Hat Ceph Storage 8 | affected |
| ||||||
| Red Hat | Red Hat Developer Hub | affected |
| ||||||
| Nodemailer | Nodemailer | unaffected |
|
Configuration 1
- < 7.0.11
Configuration 2
- 2.0
- 8.0
- n/a
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel9
Fix deferred
Red Hat Ceph Storage 8
rhceph/grafana-rhel9
Fix deferred
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Fix deferred | n/a |
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Fix deferred | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | n/a |
nodemailer
npm
Introduced 3.0.0 Fixed 7.0.11org.webjars.npm:nodemailer
Maven
Introduced 3.0.0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | nodemailer | 3.0.0 | 7.0.11 |
| Maven | org.webjars.npm:nodemailer | 3.0.0 | not fixed |
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Red Hat statement
This vulnerability is rated Moderate for Red Hat products that utilize Nodemailer, as a specially crafted email address header can trigger infinite recursion in the address parser. This can lead to a denial of service, causing the affected service to crash immediately. Exploitation does not require authentication and can be achieved with a single request.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Dec 18, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.56% (0.00556) | 44.28th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.41% (0.00409) | 32.37th | v5 (v2026.06.15) |
| Dec 18, 2025 | 0.04% (0.00042) | 12.70th | v4 (v2025.03.14) |
References (9)
- https://access.redhat.com/security/cve/CVE-2025-14874 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418133 exploitissue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-rcmh-qjqh-p98v Advisory
- https://github.com/nodemailer/nodemailer Product
- https://github.com/nodemailer/nodemailer/commit/6218b8df
- https://github.com/nodemailer/nodemailer/commit/b61b9c0cfd682b6f647754ca338373b68336a150 Patch
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-rcmh-qjqh-p98v exploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-14874
- https://www.cve.org/CVERecord?id=CVE-2025-14874
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-14874 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2418133 | exploitissue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-rcmh-qjqh-p98v | Advisory | |
| https://github.com/nodemailer/nodemailer | Product | |
| https://github.com/nodemailer/nodemailer/commit/6218b8df | ||
| https://github.com/nodemailer/nodemailer/commit/b61b9c0cfd682b6f647754ca338373b68336a150 | Patch | |
| https://github.com/nodemailer/nodemailer/security/advisories/GHSA-rcmh-qjqh-p98v | exploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-14874 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-14874 |
Change history (0)
No recorded changes yet.