Nodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflict
Summary
| CVE | CVE-2025-13033 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-11-14 20:15:45 UTC |
| Updated | 2026-05-11 13:16:10 UTC |
| Description | A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.000310000 probability, percentile 0.089700000 (date 2026-05-12)
Problem Types: CWE-1286 | CWE-1286 Improper Validation of Syntactic Correctness of Input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Nodemailer | Nodemailer | affected 7.0.7 semver | Not specified |
| CNA | Red Hat | Red Hat Ceph Storage 8.1 | unaffected 1777566546 * rpm | Not specified |
| CNA | Red Hat | Red Hat Developer Hub 1.9 | unaffected 1772573159 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:15979 | [email protected] | access.redhat.com | |
| github.com/nodemailer/nodemailer | [email protected] | github.com | |
| access.redhat.com/security/cve/CVE-2025-13033 | [email protected] | access.redhat.com | |
| github.com/nodemailer/nodemailer/commit/1150d99fba77280df2cfb1885c43df23... | [email protected] | github.com | |
| github.com/nodemailer/nodemailer/security/advisories/GHSA-mm7p-fcc7-pg87 | [email protected] | github.com | |
| access.redhat.com/errata/RHSA-2026:3751 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-10-07T15:03:14.483Z | Reported to Red Hat. |
| CNA | 2025-10-07T13:42:02.000Z | Made public. |
Workarounds
CNA: Currently there's no available mitigation for this flaw.
There are currently no legacy QID mappings associated with this CVE.