Executive brief
A vulnerability was found in Nodemailer, a popular library used by Node.js applications to send emails. Due to a flaw in how the library handles specially formatted email addresses, an attacker can trick the system into sending emails to an external address instead of the intended internal recipient. This could result in the leakage of sensitive information and allow attackers to bypass security filters or access controls.
Technical details
An interpretation conflict exists in Nodemailer's address parser due to improper handling of quoted local-parts containing the '@' symbol. When a recipient address is crafted with an external address embedded within quotes (e.g., "\"user@external.com\"@internal.domain"), the parser may misroute the email to the external domain instead of the RFC-compliant internal domain. This vulnerability allows for data exfiltration, bypass of domain-based access controls, and evasion of anti-spam filters. The issue was addressed in the Nodemailer repository by fixing how the addressparser handles quoted nested email strings.
Affected products
- Nodemailer Nodemailer Fixed in commit 1150d99fba77280df2cfb1885c43df23109a8626
Timeline
- 2025-10-07: other: Bug reported to Red Hat Bugzilla
- 2025-11-14: disclosed: CVE published to NVD
- 2026-03-04: patched: Red Hat Developer Hub update released
- 2026-05-11: patched: Red Hat Ceph Storage update released
References
- https://access.redhat.com/errata/RHSA-2026:15979
- https://access.redhat.com/errata/RHSA-2026:3751
- https://access.redhat.com/security/cve/CVE-2025-13033
- https://bugzilla.redhat.com/show_bug.cgi?id=2402179
- https://github.com/nodemailer/nodemailer
- https://github.com/nodemailer/nodemailer/commit/1150d99fba77280df2cfb1885c43df23109a8626
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-mm7p-fcc7-pg87