Update npm package nodemailer to v10 [SECURITY] - #9880
Open
hash-dependencies[bot] wants to merge 1 commit into
Open
hash-dependencies[bot] wants to merge 1 commit into
hash-dependencies[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
3 Skipped Deployments
|
PR SummaryLow Risk Overview The target release includes the fix for GHSA-6vj9-mwq6-2f5v, where a process-global DNS cache could reuse another transport’s TLS Reviewed by Cursor Bugbot for commit 42a1925. Bugbot is set up for automated code reviews on this repo. Configure here. |
Contributor
Dependency ReviewThe following issues were found:
Vulnerabilitiesapps/hash-api/package.json
yarn.lock
OpenSSF Scorecard
Scanned Files
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
9.1.1→10.0.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Nodemailer: Process-global DNS cache reuses TLS
servernameacross transports, enabling cross-tenant SMTP credential disclosureGHSA-6vj9-mwq6-2f5v
More information
Details
Summary
Nodemailer's process-global DNS cache is keyed only by
host, but each cache entry also stores the caller-specific TLSservername. When two direct SMTPS transports use the same DNS host with differenttls.servernamevalues, the first transport's server name is returned to the second transport and overwrites its explicitly configured value.As a result, Nodemailer sends the wrong SNI value and verifies the peer certificate against the wrong identity. In a multi-tenant service or SNI-routed SMTP gateway, one tenant can prime the cache so that a victim transport connects to the attacker's TLS virtual host, accepts the attacker's certificate with
rejectUnauthorized: true, and sends the victim's SMTP credentials to it.Affected component
nodemailer10.0.140d52215aac65b811d7e131bc916f68605efd9d25.0.0and10.0.1>= 5.0.0, <= 10.0.1secure: true) where different transports use the same non-IPhostand different TLSservernamevaluesThe vulnerable cache implementation was introduced in commit
6859b5dd96c8d9f0070a3169a877181b71df4a3bon 2018-12-28. Git history showsv5.0.0as the first release tag containing that commit. The behavior remains present inv10.0.1.Details
Root cause
src/shared/index.tsdefines one module-global DNS cache, keyed only by the DNS host:Although the cache key contains only
host, the cached value contains both DNS addresses and the request-specific TLS identity:On a cache hit,
resolveHostname()returns the cachedservernamewithout considering the current call'soptions.servername:formatDNSValue()copies that stale value into the result:For a direct TLS connection,
SMTPConnection.connect()initially copies the current transport's TLS configuration intoopts._resolveAndConnect()then overwrites every truthy field with the cached resolver result, includingopts.servername:The resulting
optsobject is passed totls.connect(). Node therefore sends the cached server name as SNI and verifies the certificate against that cached name, rather than against the server name explicitly configured for the current transport.The default DNS cache TTL is five minutes:
Code path
Relevant source locations in the tested revision
src/shared/index.ts:184— five-minute default cache TTLsrc/shared/index.ts:245— process-global cache keyed by hostsrc/shared/index.ts:247-262— cachedservernamereturned byformatDNSValue()src/shared/index.ts:292-323— host-only lookup and cache-hit returnsrc/shared/index.ts:350-359— caller-specificservernamestored in host-only cachesrc/smtp-connection/index.ts:713-729— direct TLS options and resolver callsrc/smtp-connection/index.ts:741-763— cached fields overwrite current connection optionsPoC
Prerequisites
20.20.2)10.0.1No external SMTP server or network access is required.
1. Generate a certificate for only
attacker.testCreate
openssl.cnf:Generate the certificate and private key:
2. Save the following as
poc-dns-cache-servername-confusion.mjsAdjust the two import paths if the PoC is not saved beside the repository checkout.
3. Build and run
From the Nodemailer checkout:
Observed result
{ "attackerConfiguredServername": "attacker.test", "victimConfiguredServername": "victim.test", "serverObservedSniForBothConnections": [ "attacker.test", "attacker.test" ], "serverReceivedCredentials": [ "\\u0000attacker@example.test\\u0000attacker-secret", "\\u0000victim@example.test\\u0000victim-secret" ] }The victim configured
victim.test, but the server observesattacker.testfor both handshakes. The local certificate contains onlyattacker.test, yet the victim connection succeeds withrejectUnauthorized: trueand then sends the victim's username and password.Expected result
The second connection must use
victim.testfor SNI and certificate hostname verification. With the PoC certificate, it should fail with a hostname mismatch before SMTP authentication occurs. It must never transmit victim credentials after validating the peer asattacker.test.Impact
The vulnerability affects long-running applications that create multiple Nodemailer transports in one process and let separate tenants or security domains configure transports that share a DNS
host. A practical example is an email platform whose SMTP gateway uses SNI to route several customer-specific SMTP endpoints behind one hostname.An attacker who can create or exercise one transport can prime the global cache with the shared host and the attacker's
tls.servername. During the cache lifetime, a victim's direct SMTPS connection to that host can:Possession of SMTP credentials may also let the attacker read or change mail account state where the provider reuses those credentials, or send mail as the victim. The exact secondary impact depends on the SMTP provider.
Where the attacker cannot control an SNI virtual host, stale cross-transport SNI can still cause certificate mismatch failures and cross-tenant availability impact.
Preconditions and limitations
hostcache key and differenttls.servernamevalues.secure: true). The STARTTLS upgrade path constructs TLS options separately and is not claimed vulnerable by this report.Suggested remediation
The DNS cache should store DNS data only.
servernameis connection-specific TLS policy and should not be persisted in a cache keyed solely by hostname.One approach is to remove
servernamefromDnsCacheValueand derive the returned value from the current request on every path:As defense in depth,
_resolveAndConnect()should not overwrite an explicitly configuredopts.servernamewith resolver metadata. Keying the cache by both host and server name would avoid this particular collision, but keeping TLS identity out of a DNS-address cache provides a cleaner separation.A regression test should create two direct-TLS transports in the same process with the same DNS host and different explicit server names, then assert that each TLS connection observes and verifies its own configured name regardless of cache order.
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodemailer/nodemailer (nodemailer)
v10.0.2Compare Source
Bug Fixes
v10.0.1Compare Source
Bug Fixes
v10.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.