{"id":"CVE-2021-23400","aliases":["GHSA-hwqf-gcqm-7353"],"url":"https://o3.security/vulnerability/CVE-2021-23400","summary":"Header injection in nodemailer","details":"The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.","published":"2021-06-29T12:15:08.363Z","modified":"2026-07-08T21:26:01.874187Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"nodemailer","fixedVersion":"6.6.1"}],"fix":{"url":"https://github.com/nodemailer/nodemailer/commit/7e02648cc8cd863f5085bad3cd09087bccf84b9f","label":"nodemailer/nodemailer@7e02648"},"references":[{"type":"ADVISORY","url":"https://github.com/nodemailer/nodemailer/issues/1289"},{"type":"FIX","url":"https://github.com/nodemailer/nodemailer/commit/7e02648cc8cd863f5085bad3cd09087bccf84b9f"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1314737"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-NODEMAILER-1296415"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:26:01.874187Z"}}