CVE-2025-14874
Unknown
Unknown - Not Provided
Denial of Service in Nodemailer via Recursive Address Parser
Publication date: 2025-12-18
Last updated on: 2025-12-18
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nodemailer | nodemailer | 7.0.10 |
| nodemailer | nodemailer | 7.0.11 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-703 | The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product. |