Skip to content

[Snyk] Upgrade nodemailer from 7.0.5 to 7.0.11#22

Open
DavidUmunna wants to merge 1 commit into
mainfrom
snyk-upgrade-6ed90e37f20bdeda7de35c4070832329
Open

[Snyk] Upgrade nodemailer from 7.0.5 to 7.0.11#22
DavidUmunna wants to merge 1 commit into
mainfrom
snyk-upgrade-6ed90e37f20bdeda7de35c4070832329

Conversation

@DavidUmunna
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade nodemailer from 7.0.5 to 7.0.11.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.

  • The recommended version was released 25 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Uncontrolled Recursion
SNYK-JS-NODEMAILER-14157156
666 Proof of Concept
medium severity Interpretation Conflict
SNYK-JS-NODEMAILER-13378253
666 Proof of Concept
Release notes
Package name: nodemailer
  • 7.0.11 - 2025-11-26

    7.0.11 (2025-11-26)

    Bug Fixes

    • prevent stack overflow DoS in addressparser with deeply nested groups (b61b9c0)
  • 7.0.10 - 2025-10-23

    7.0.10 (2025-10-23)

    Bug Fixes

    • Increase data URI size limit from 100KB to 50MB and preserve content type (28dbf3f)
  • 7.0.9 - 2025-10-07

    7.0.9 (2025-10-07)

    Bug Fixes

    • release: Trying to fix release proecess by upgrading Node version in runner (579fce4)
  • 7.0.7 - 2025-10-05

    7.0.7 (2025-10-05)

    Bug Fixes

    • addressparser: Fixed addressparser handling of quoted nested email addresses (1150d99)
    • dns: add memory leak prevention for DNS cache (0240d67)
    • linter: Updated eslint and created prettier formatting task (df13b74)
    • refresh expired DNS cache on error (#1759) (ea0fc5a)
    • resolve linter errors in DNS cache tests (3b8982c)
  • 7.0.6 - 2025-08-30

    7.0.6 (2025-08-27)

    Bug Fixes

    • encoder: avoid silent data loss by properly flushing trailing base64 (#1747) (01ae76f)
    • handle multiple XOAUTH2 token requests correctly (#1754) (dbe0028)
    • ReDoS vulnerability in parseDataURI and _processDataUrl (#1755) (90b3e24)
  • 7.0.5 - 2025-07-07

    7.0.5 (2025-07-07)

    Bug Fixes

    • updated well known delivery service list (fa2724b)
from nodemailer GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade nodemailer from 7.0.5 to 7.0.11.

See this package in npm:
nodemailer

See this project in Snyk:
https://app.snyk.io/org/davidumunna/project/13221649-54aa-4adb-ba27-2649b33e9450?utm_source=github&utm_medium=referral&page=upgrade-pr
@vercel
Copy link
Copy Markdown

vercel Bot commented Dec 21, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
procurement-api Ready Ready Preview, Comment Dec 21, 2025 7:34am

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants