Package compatibility
Nodemailer
Node.js requirements from npm Registry (engines.node) for the nodemailer package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Nodemailer 0.1
tip 0.1.24Node.js *
Source: package metadata
No Node.js VersionLine evaluations are available for Nodemailer 0.1 yet.
Nodemailer 0.2
tip 0.2.4Node.js *
Source: package metadata
No Node.js VersionLine evaluations are available for Nodemailer 0.2 yet.
Nodemailer 0.3
tip 0.3.20Node.js *
Source: package metadata
No Node.js VersionLine evaluations are available for Nodemailer 0.3 yet.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- GHSA-p6gq-j5cr-w38f
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
- Affected:
- <9.0.1
- Fixed in:
- 9.0.1
- Source:
- OSV source
- GHSA-268h-hp4c-crq3
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-wqvq-jvpq-h66f
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-r7g4-qg5f-qqm2
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
- Affected:
- <8.0.8
- Fixed in:
- 8.0.8
- Source:
- OSV source
- GHSA-vvjj-xcjg-gr5g
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
- Affected:
- <8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source
- GHSA-c7w3-x93f-qmm8
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
- Affected:
- <8.0.4
- Fixed in:
- 8.0.4
- Source:
- OSV source
- CVE-2025-14874GHSA-rcmh-qjqh-p98v
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
- Affected:
- >=3.0.0,<7.0.11
- Fixed in:
- 7.0.11
- Source:
- OSV source · Advisory
- CVE-2025-13033GHSA-mm7p-fcc7-pg87
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
- Affected:
- <7.0.7
- Fixed in:
- 7.0.7
- Source:
- OSV source · Advisory
- GHSA-9h6g-pr28-7cqp
nodemailer ReDoS when trying to send a specially crafted email
- Affected:
- <6.9.9
- Fixed in:
- 6.9.9
- Source:
- OSV source
- CVE-2021-23400GHSA-hwqf-gcqm-7353
Header injection in nodemailer
- Affected:
- <6.6.1
- Fixed in:
- 6.6.1
- Source:
- OSV source · Advisory
- CVE-2020-7769GHSA-48ww-j4fc-435p
Command injection in nodemailer
- Affected:
- <6.4.16
- Fixed in:
- 6.4.16
- Source:
- OSV source · Advisory
