SMTP Injection Vulnerability in Jakarta Mail by Eclipse
CVE-2025-7962
6MEDIUM
What is CVE-2025-7962?
Jakarta Mail version 2.2 is prone to a SMTP Injection vulnerability whereby attackers can exploit the handling of UTF-8 characters, specifically and , to manipulate email message flow. This flaw enables unauthorized separation of messages, leading to potential exploitation in email communications. Proper validation and sanitization methods should be employed to counteract these types of attacks.
Affected Version(s)
Jakarta Mail 1.6.8
Jakarta Mail 2.0.2