Executive brief
Nodemailer, a widely-used Node.js library for sending emails, disables TLS certificate validation when fetching OAuth2 authentication tokens. An attacker positioned on the network between a Nodemailer client and an OAuth provider can intercept and steal sensitive credentials including client secrets, refresh tokens, and access tokens, enabling unauthorized email sending and mailbox compromise.
Technical details
The vulnerability exists in lib/fetch/index.js where Nodemailer sets rejectUnauthorized: false in its internal HTTPS client, disabling TLS peer certificate verification globally. This allows self-signed and invalid certificates to be accepted, hostname validation to be bypassed, and attacker-controlled HTTPS endpoints to be trusted. An attacker in a man-in-the-middle position can intercept OAuth2 token requests to capture OAuth client_secret, refresh_token, and access tokens. The vulnerability affects versions <= 8.0.7 and is patched in version 8.0.8. Attack vector is network with high attack complexity (requires MITM positioning).
Affected products
- Nodemailer Nodemailer <= 8.0.7
Timeline
- 2026-05-26: disclosed
- 2026-05-26: patched: Fixed in version 8.0.8