CVE-2025-14874
Nodemailer: nodemailer: denial of service via crafted email address header
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
nodemailer · nodemailerRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2Red Hat · Red Hat Ceph Storage 8Red Hat · Red Hat Developer HubQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/security/cve/CVE-2025-14874https://bugzilla.redhat.com/show_bug.cgi?id=2418133https://github.com/nodemailer/nodemailerhttps://github.com/nodemailer/nodemailer/commit/b61b9c0cfd682b6f647754ca338373b68336a150https://github.com/nodemailer/nodemailer/security/advisories/GHSA-rcmh-qjqh-p98v