Package compatibility
Nodemailer 0.2
What Node.js versions does this Nodemailer version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- *
- Tip version
- 0.2.4
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
No Node.js VersionLine evaluations are available for Nodemailer 0.2 yet.
Other Nodemailer lines
Security
Advisories affecting Nodemailer 0.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 10
- Known exploited
- 0
- Highest CVSS
- —
- GHSA-p6gq-j5cr-w38f
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
- Affected:
- <9.0.1
- Fixed in:
- 9.0.1
- Source:
- OSV source
- GHSA-268h-hp4c-crq3
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-wqvq-jvpq-h66f
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-r7g4-qg5f-qqm2
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
- Affected:
- <8.0.8
- Fixed in:
- 8.0.8
- Source:
- OSV source
- GHSA-vvjj-xcjg-gr5g
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
- Affected:
- <8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source
- GHSA-c7w3-x93f-qmm8
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
- Affected:
- <8.0.4
- Fixed in:
- 8.0.4
- Source:
- OSV source
- CVE-2025-13033GHSA-mm7p-fcc7-pg87
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
- Affected:
- <7.0.7
- Fixed in:
- 7.0.7
- Source:
- OSV source · Advisory
- GHSA-9h6g-pr28-7cqp
nodemailer ReDoS when trying to send a specially crafted email
- Affected:
- <6.9.9
- Fixed in:
- 6.9.9
- Source:
- OSV source
- CVE-2021-23400GHSA-hwqf-gcqm-7353
Header injection in nodemailer
- Affected:
- <6.6.1
- Fixed in:
- 6.6.1
- Source:
- OSV source · Advisory
- CVE-2020-7769GHSA-48ww-j4fc-435p
Command injection in nodemailer
- Affected:
- <6.4.16
- Fixed in:
- 6.4.16
- Source:
- OSV source · Advisory
