Wiz Agents & Workflows are here

CVE-2021-23400
JavaScript vulnerability analysis and mitigation

Overview

The vulnerability CVE-2021-23400 affects the Nodemailer package versions before 6.6.1. This HTTP Header Injection vulnerability was discovered and disclosed on May 22, 2021, and affects the email sending functionality in Node.js applications. The vulnerability occurs when unsanitized user input containing newlines and carriage returns is passed into an address object (CVE Mitre).

Technical details

The vulnerability allows for HTTP Header Injection through the address object in Nodemailer. When user input containing newlines and carriage returns is passed into an address object without proper sanitization, it can lead to header injection in the email. The vulnerability has a CVSS v3.1 base score of 6.3 (medium severity), with attack vector being Network, attack complexity Low, requiring no privileges, but needing user interaction (Snyk Report).

Impact

If exploited, this vulnerability could allow attackers to inject additional email headers through malicious input in the address field. This could potentially lead to email header manipulation and possibly affect the email delivery system's behavior (GitHub Issue).

Mitigation and workarounds

The vulnerability was fixed in Nodemailer version 6.6.1. The fix includes proper sanitization of address fields to remove unallowed characters and prevent header injection. Users should upgrade to version 6.6.1 or later to mitigate this vulnerability (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34156CRITICAL9.9
  • JavaScriptJavaScript
  • @nocobase/plugin-workflow-javascript
NoYesMar 30, 2026
CVE-2026-34363HIGH8.2
  • JavaScriptJavaScript
  • parse-server
NoYesMar 30, 2026
CVE-2026-33949HIGH8.1
  • JavaScriptJavaScript
  • @tinacms/graphql
NoYesMar 30, 2026
CVE-2026-34043MEDIUM5.9
  • JavaScriptJavaScript
  • serialize-javascript
NoYesMar 31, 2026
CVE-2026-34373MEDIUM5.3
  • JavaScriptJavaScript
  • parse-server
NoYesMar 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management