CVE-2025-7962
In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
- EPSS probability
- 0.77%
- CWE
- CWE-147
- Published
- 2025-07-21
- Last modified
- 2026-06-23
Affected products
- Eclipse Foundation Jakarta Mail
- Eclipse Foundation Jakarta Mail
Weakness type
Related vulnerabilities
- CVE-2024-50349 — Git does not sanitize URLs when asking for credentials interactively
- CVE-2024-52006 — Newline confusion in credential helpers can lead to credential exfiltration in git
- CVE-2024-52505 — matrix-appservice-irc allows IRC Command injection in provisioning API
- CVE-2023-4393 — HTML and SMTP Injection in LiquidFiles