Package compatibility

Nodemailer 0.2

What Node.js versions does this Nodemailer version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
*
Tip version
0.2.4
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

No Node.js VersionLine evaluations are available for Nodemailer 0.2 yet.

Other Nodemailer lines

Security

Advisories affecting Nodemailer 0.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
10
Known exploited
0
Highest CVSS
  • GHSA-p6gq-j5cr-w38f

    Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

    Affected:
    <9.0.1
    Fixed in:
    9.0.1
    Source:
    OSV source
  • GHSA-268h-hp4c-crq3

    Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

    Affected:
    <8.0.9
    Fixed in:
    8.0.9
    Source:
    OSV source
  • GHSA-wqvq-jvpq-h66f

    Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

    Affected:
    <8.0.9
    Fixed in:
    8.0.9
    Source:
    OSV source
  • GHSA-r7g4-qg5f-qqm2

    Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

    Affected:
    <8.0.8
    Fixed in:
    8.0.8
    Source:
    OSV source
  • GHSA-vvjj-xcjg-gr5g

    Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

    Affected:
    <8.0.5
    Fixed in:
    8.0.5
    Source:
    OSV source
  • GHSA-c7w3-x93f-qmm8

    Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter

    Affected:
    <8.0.4
    Fixed in:
    8.0.4
    Source:
    OSV source
  • CVE-2025-13033GHSA-mm7p-fcc7-pg87

    Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict

    Affected:
    <7.0.7
    Fixed in:
    7.0.7
    Source:
    OSV source · Advisory
  • GHSA-9h6g-pr28-7cqp

    nodemailer ReDoS when trying to send a specially crafted email

    Affected:
    <6.9.9
    Fixed in:
    6.9.9
    Source:
    OSV source
  • CVE-2021-23400GHSA-hwqf-gcqm-7353

    Header injection in nodemailer

    Affected:
    <6.6.1
    Fixed in:
    6.6.1
    Source:
    OSV source · Advisory
  • CVE-2020-7769GHSA-48ww-j4fc-435p

    Command injection in nodemailer

    Affected:
    <6.4.16
    Fixed in:
    6.4.16
    Source:
    OSV source · Advisory