Package compatibility

Nodemailer 7

What Node.js versions does this Nodemailer version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=6.0.0
Tip version
7.0.13
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Nodemailer lines

Security

Advisories affecting Nodemailer 7 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
6
Known exploited
0
Highest CVSS
  • GHSA-p6gq-j5cr-w38f

    Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

    Affected:
    <9.0.1
    Fixed in:
    9.0.1
    Source:
    OSV source
  • GHSA-268h-hp4c-crq3

    Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

    Affected:
    <8.0.9
    Fixed in:
    8.0.9
    Source:
    OSV source
  • GHSA-wqvq-jvpq-h66f

    Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

    Affected:
    <8.0.9
    Fixed in:
    8.0.9
    Source:
    OSV source
  • GHSA-r7g4-qg5f-qqm2

    Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

    Affected:
    <8.0.8
    Fixed in:
    8.0.8
    Source:
    OSV source
  • GHSA-vvjj-xcjg-gr5g

    Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

    Affected:
    <8.0.5
    Fixed in:
    8.0.5
    Source:
    OSV source
  • GHSA-c7w3-x93f-qmm8

    Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter

    Affected:
    <8.0.4
    Fixed in:
    8.0.4
    Source:
    OSV source