Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2025-13033

PUBLISHED 11.05.2026

CNA: redhat

Nodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflict

Обновлено: 11.05.2026
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.

CWE

Идентификатор Описание
CWE-1286 The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

CVSS

Оценка Severity Версия Базовый вектор
7.5 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.03% LOW 9.20 23.05.2026

Доп. Информация

Product Status

nodemailer
Product: nodemailer
Vendor: nodemailer
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 7.0.7 affected
Red Hat Ceph Storage 8.1
Product: Red Hat Ceph Storage 8.1
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1777566546 до * unaffected
СPE:
  • cpe:/a:redhat:ceph_storage:8.1::el9
Red Hat Developer Hub 1.9
Product: Red Hat Developer Hub 1.9
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1772573159 до * unaffected
СPE:
  • cpe:/a:redhat:rhdh:1.9::el9
Red Hat Advanced Cluster Management for Kubernetes 2
Product: Red Hat Advanced Cluster Management for Kubernetes 2
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:acm:2
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 14.11.2025
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none yes partial 2.0.3 14.11.2025

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.