Nodemailer is a widely used Node.js email-transmission library whose vulnerability footprint concentrates in the core mailer and its companion mailparser component, reflecting the complexity of email composition and parsing. Observed weaknesses cluster around input-handling and output-generation issues, including argument injection, cross-site scripting, and improper exception handling that arise in message construction and downstream consumption of email content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nodemailer over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7769CRITICAL This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails. | Nov 12, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-23400HIGH The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address objec | Jun 29, 2021 | 8.8 | 26 | NO | NO |
CVE-2025-14874HIGH A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | Dec 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2026-3455MEDIUM Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email con | Mar 3, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nodemailer.
Media articles that mention a CVE ID that affects a product developed by Nodemailer — matched by CVE ID, not by vendor name.