The Lab · 2026-03-31 17:27:28 · GitHub Issues
A critical security vulnerability in the widely-used Nodemailer library exposes applications to email misrouting. The flaw, tracked as CVE-2025-13033, stems from the library's incorrect handling of quoted local-parts containing the '@' symbol within email addresses. This parsing error can cause emails to be delivered t...
The Lab · 2026-04-08 17:27:19 · GitHub Issues
A critical vulnerability in the widely-used Nodemailer library exposes email systems to message misrouting. The flaw, tracked as CVE-2025-13033, stems from the library's incorrect parsing of email addresses containing quoted local-parts with the '@' symbol. This parsing error can cause the system to extract and route m...
The Lab · 2026-04-08 18:27:25 · GitHub Issues
A critical security flaw in the widely-used Nodemailer library has been patched, forcing a major version update to v8. The vulnerability, tracked as CVE-2025-13033, stems from a flaw in the library's email address parser that could cause emails to be misrouted to unintended recipients. This is not a theoretical bug; it...
The Lab · 2026-04-09 02:27:06 · GitHub Issues
A critical vulnerability in the widely-used Nodemailer library exposes email systems to message misrouting. The flaw, tracked as CVE-2025-13033, stems from the library's incorrect handling of quoted local-parts containing the '@' symbol. This parsing error can cause emails to be sent to an unintended domain instead of ...