Skip to content

Conversation

@nerdy-tech-com-gitub
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade nodemailer from 6.9.13 to 7.0.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 12 versions ahead of your current version.

  • The recommended version was released a month ago.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Insecure Randomness
SNYK-JS-UNDICI-8641354
51 Proof of Concept
high severity Incorrect Authorization
SNYK-JS-VITE-9512410
51 Mature
high severity Incorrect Authorization
SNYK-JS-VITE-9653016
51 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
51 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
51 Proof of Concept
high severity Improper Neutralization of Special Elements in Data Query Logic
SNYK-JS-MONGOOSE-8446504
51 No Known Exploit
high severity Improper Neutralization of Special Elements in Data Query Logic
SNYK-JS-MONGOOSE-8623536
51 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-NUXT-7640974
51 No Known Exploit
high severity Acceptance of Extraneous Untrusted Data With Trusted Data
SNYK-JS-NUXT-9486043
51 No Known Exploit
high severity Directory Traversal
SNYK-JS-NUXTDEVTOOLS-7640977
51 Proof of Concept
medium severity Directory Traversal
SNYK-JS-SUPABASEAUTHJS-10255365
51 No Known Exploit
medium severity Information Exposure
SNYK-JS-VITE-8023174
51 Proof of Concept
medium severity Origin Validation Error
SNYK-JS-VITE-8648411
51 Proof of Concept
medium severity Access Control Bypass
SNYK-JS-VITE-9576207
51 Proof of Concept
medium severity Information Exposure
SNYK-JS-VITE-9685035
51 Proof of Concept
medium severity Directory Traversal
SNYK-JS-VITE-9919777
51 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-VUETEMPLATECOMPILER-7554675
51 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697
51 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELRUNTIME-10044504
51 Proof of Concept
medium severity Open Redirect
SNYK-JS-KOA-10944994
51 Proof of Concept
medium severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
51 No Known Exploit
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
51 No Known Exploit
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
51 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-NUXT-7640972
51 Proof of Concept
medium severity Origin Validation Error
SNYK-JS-NUXTVITEBUILDER-8663232
51 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-PARSEGITCONFIG-9403763
51 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
51 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-ROLLUP-8073097
51 Proof of Concept
low severity Directory Traversal
SNYK-JS-SIRV-12558119
51 Proof of Concept
low severity Missing Release of Memory after Effective Lifetime
SNYK-JS-UNDICI-10176064
51 Proof of Concept
low severity Relative Path Traversal
SNYK-JS-VITE-12558116
51 Proof of Concept
low severity Cross-site Scripting (XSS)
SNYK-JS-VITE-8022916
51 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-VUETEMPLATECOMPILER-8219888
51 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
51 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
51 Proof of Concept
critical severity Prototype Pollution
SNYK-JS-DEVALUE-12205530
51 Proof of Concept
critical severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-KOA-8720152
51 No Known Exploit
low severity Cross-site Scripting (XSS)
SNYK-JS-KOA-9679272
51 Proof of Concept
low severity Directory Traversal
SNYK-JS-NUXT-12878602
51 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
51 No Known Exploit
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
51 No Known Exploit
Release notes
Package name: nodemailer
  • 7.0.6 - 2025-08-30

    7.0.6 (2025-08-27)

    Bug Fixes

    • encoder: avoid silent data loss by properly flushing trailing base64 (#1747) (01ae76f)
    • handle multiple XOAUTH2 token requests correctly (#1754) (dbe0028)
    • ReDoS vulnerability in parseDataURI and _processDataUrl (#1755) (90b3e24)
  • 7.0.5 - 2025-07-07

    7.0.5 (2025-07-07)

    Bug Fixes

    • updated well known delivery service list (fa2724b)
  • 7.0.4 - 2025-06-29

    7.0.4 (2025-06-29)

    Bug Fixes

    • pools: Emit 'clear' once transporter is idle and all connections are closed (839e286)
    • smtp-connection: jsdoc public annotation for socket (#1741) (c45c84f)
    • well-known-services: Added AliyunQiye (bb9e6da)
  • 7.0.3 - 2025-05-08

    7.0.3 (2025-05-08)

    Bug Fixes

    • attachments: Set the default transfer encoding for message/rfc822 attachments as '7bit' (007d5f3)
  • 7.0.2 - 2025-05-04

    7.0.2 (2025-05-04)

    Bug Fixes

    • ses: Fixed structured from header (faa9a5e)
  • 7.0.1 - 2025-05-04

    7.0.1 (2025-05-04)

    Bug Fixes

    • ses: Use formatted FromEmailAddress for SES emails (821cd09)
  • 7.0.0 - 2025-05-03

    7.0.0 (2025-05-03)

    ⚠ BREAKING CHANGES

    • SESv2 SDK support, removed older SES SDK v2 and v3 , removed SES rate limiting and idling features

    See SES Transport Docs for updated usage details

    Features

    • SESv2 SDK support, removed older SES SDK v2 and v3 , removed SES rate limiting and idling features (15db667)
  • 6.10.1 - 2025-04-13

    6.10.1 (2025-02-06)

    Bug Fixes

  • 6.10.0 - 2025-01-23

    6.10.0 (2025-01-23)

    Features

    • services: add Seznam email service configuration (#1695) (d1ae0a8)

    Bug Fixes

    • proxy: Set error and timeout errors for proxied sockets (aa0c99c)
  • 6.9.16 - 2024-10-28

    6.9.16 (2024-10-28)

    Bug Fixes

    • addressparser: Correctly detect if user local part is attached to domain part (f2096c5)
  • 6.9.15 - 2024-09-03
  • 6.9.14 - 2024-06-19
  • 6.9.13 - 2024-03-20
from nodemailer GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade nodemailer from 6.9.13 to 7.0.6.

See this package in npm:
nodemailer

See this project in Snyk:
https://app.snyk.io/org/nerds-github/project/ef708957-d107-4807-bb9b-ffb67ea15337?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants