THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wmmp-3585-3rmp (medium) — Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

[GHSA] GHSA-wmmp-3585-3rmp (medium) — Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

highgithub_advisoriesPublished 2026-09-08

GHSA-wmmp-3585-3rmp Severity: medium CVE: None

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

### Summary

Nodemailer resolves an international (IDN / non-ASCII) recipient **domain** to a different Punycode `xn--` label than every UTS‑46‑conformant parser (web browsers, the WHATWG URL Standard, Node's `url.domainToASCII`, Python's `idna

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wmmp-3585-3rmp