Package compatibility
Nodemailer 7
What Node.js versions does this Nodemailer version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=6.0.0
- Tip version
- 7.0.13
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Nodemailer lines
Security
Advisories affecting Nodemailer 7 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 6
- Known exploited
- 0
- Highest CVSS
- —
- GHSA-p6gq-j5cr-w38f
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
- Affected:
- <9.0.1
- Fixed in:
- 9.0.1
- Source:
- OSV source
- GHSA-268h-hp4c-crq3
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-wqvq-jvpq-h66f
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
- Affected:
- <8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source
- GHSA-r7g4-qg5f-qqm2
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
- Affected:
- <8.0.8
- Fixed in:
- 8.0.8
- Source:
- OSV source
- GHSA-vvjj-xcjg-gr5g
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
- Affected:
- <8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source
- GHSA-c7w3-x93f-qmm8
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
- Affected:
- <8.0.4
- Fixed in:
- 8.0.4
- Source:
- OSV source
