This advisory has been withdrawn because it is a duplicate of GHSA-r7g4-qg5f-qqm2. This link is maintained to preserve external references.
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.
{
"cwe_ids": [
"CWE-295"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:51:40Z",
"nvd_published_at": "2026-08-31T09:17:04Z",
"severity": "HIGH"
}