Medium severity6.3NVD Advisory· Published Jun 29, 2021· Updated Jun 17, 2026
CVE-2021-23400
CVE-2021-23400
Description
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nodemailernpm | < 6.6.1 | 6.6.1 |
Affected products
3- nodemailer/nodemailerdescription
Patches
Vulnerability mechanics
References
6- github.com/nodemailer/nodemailer/commit/7e02648cc8cd863f5085bad3cd09087bccf84b9fnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1314737nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-NODEMAILER-1296415nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hwqf-gcqm-7353ghsaADVISORY
- github.com/nodemailer/nodemailer/issues/1289nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23400ghsaADVISORY
News mentions
0No linked articles in our index yet.