THREAT OPS › Threat News › [GHSA] GHSA-wmmp-3585-3rmp (medium) — Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
[GHSA] GHSA-wmmp-3585-3rmp (medium) — Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
GHSA-wmmp-3585-3rmp Severity: medium CVE: None
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
### Summary
Nodemailer resolves an international (IDN / non-ASCII) recipient **domain** to a different Punycode `xn--` label than every UTS‑46‑conformant parser (web browsers, the WHATWG URL Standard, Node's `url.domainToASCII`, Python's `idna
Indicators of compromise
- app@company.comemail
- victim@xn--company-pka.comemail
- user@attacker.exampleemail
- xn--mi7cd4afch9d.comdomain
- xn--exmple-qta.comdomain
- xn--example-vge.comdomain
- u00adny.comdomain
Original source: https://github.com/advisories/GHSA-wmmp-3585-3rmp