Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nodemailer to version 10.0.2 or higher.
nodemailer is an Easy as cake e-mail sending from your Node.js applications
Affected versions of this package are vulnerable to Uncontrolled Recursion via _parseAddresses in src/mime-node/index.ts when a recipient field is supplied as a deeply nested array. The native array-to-string conversion applied before passing the value to addressparser recurses once per nesting level, so a recipient wrapped in roughly a few thousand arrays (approximately 10 KB of JSON) exhausts the call stack and causes a RangeError. Because the compile step of sendMail was not wrapped in a try/catch, the synchronous throw escapes the callback chain and can crash the process.
Note: This is only exploitable if the caller does not catch the complete synchronous invocation of sendMail.