WhisperX tag archive

#smtp

This page collects WhisperX intelligence signals tagged #smtp. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (7)

The Lab · 2026-03-27 06:26:58 · GitHub Issues

1. Nodemailer v8 Security Patch: Critical SMTP Command Injection Vulnerability Fixed

A critical security vulnerability in the widely-used Nodemailer email library has been patched in its latest major version. The flaw, tracked as GHSA-c7w3-x93f-qmm8, allowed for arbitrary SMTP command injection, posing a severe risk to any application using the library to send mail. The vulnerability was triggered when...

The Lab · 2026-03-27 10:27:08 · GitHub Issues

2. Nodemailer v8 Security Patch: Critical SMTP Command Injection Vulnerability (GHSA-c7w3-x93f-qmm8)

A critical security vulnerability in the widely-used Nodemailer library allows for arbitrary SMTP command injection, posing a direct threat to email infrastructure integrity. The flaw, tracked as GHSA-c7w3-x93f-qmm8, is triggered when a custom `envelope` object containing a `size` property with CRLF characters (`\r\n`)...

The Lab · 2026-03-30 12:27:07 · GitHub Issues

3. Nodemailer v8 Security Patch: Critical SMTP Command Injection Vulnerability Fixed

A critical security vulnerability in the widely-used Nodemailer email-sending library has been patched in its new major version, v8. The flaw, tracked as GHSA-c7w3-x93f-qmm8, allowed for arbitrary SMTP command injection, posing a severe risk to any application using the library to send mail. This is not a theoretical w...

The Lab · 2026-03-30 12:27:16 · GitHub Issues

4. Nodemailer v8.0.4 Patches Critical SMTP Command Injection Vulnerability (GHSA-c7w3-x93f-qmm8)

A critical security flaw in the widely-used Nodemailer library allowed attackers to silently hijack email delivery by injecting arbitrary SMTP commands. The vulnerability, tracked as GHSA-c7w3-x93f-qmm8, was present when a custom `envelope` object with a `size` property was passed to the `sendMail()` function. If this ...

The Lab · 2026-04-01 10:26:56 · GitHub Issues

5. Nodemailer Security Flaw: SMTP Command Injection via Unfiltered CRLF in 'size' Property

A critical security vulnerability in the widely-used Nodemailer email library allows for arbitrary SMTP command injection. The flaw, tracked as GHSA-c7w3-x93f-qmm8, exists when a custom `envelope` object containing a `size` property is passed to the `sendMail()` function. If the `size` value includes carriage return an...