Product
Nodemailer versions before 10.0.6 are vulnerable to a Regular Expression Denial of Service (ReDoS) in the addressparser component, allowing attackers to block the Node.js event loop via crafted email headers.