CVE-2024-58379

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:16

Updated : 2026-09-10 15:48


NVD link : CVE-2024-58379

Mitre link : CVE-2024-58379

CVE.ORG link : CVE-2024-58379


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity