StackRadar

CVE-2024-58379

Medium

Advisory

Published 31 Jan 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 1
affected package

nodemailer ReDoS when trying to send a specially crafted email

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
nodemailernpm1.11.0, 2.7.2, 4.0.1, 4.6.8+24 more6.9.954
OSV records
GHSA-9h6g-pr28-7cqp

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
nodemailer@6.9.8
6.9.9

Open the chart page →

4,560
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
nodemailer@4.7.0
6.9.9

Open the chart page →

1,866
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nodemailer@6.5.0
6.9.9

Open the chart page →

9,968
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
nodemailer@6.6.5
6.9.9

Open the chart page →

4,744
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
nodemailer@6.9.1
6.9.9

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
nodemailer@6.4.6
6.9.9

Open the chart page →

3,638
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
nodemailer@6.7.5
6.9.9

Open the chart page →

14,679
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
nodemailer@6.7.3
6.9.9

Open the chart page →

4,017
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
nodemailer@6.7.2
6.9.9

Open the chart page →

3,129
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2024-58379.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
nodemailer@6.9.1
6.9.9

Open the chart page →

5,459

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sct/overseerr:1.35.06197516c9d7b
nodemailer@6.8.0
6.9.9
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nodemailer@5.1.1
6.9.9
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nodemailer@6.5.0
6.9.9
1
quay.io/wekan/wekan:v5.65cb17600883a3
nodemailer@6.4.6
6.9.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.