SMTP Injection Vulnerability in Jakarta Mail by Eclipse
CVE-2025-7962
6MEDIUM
What is CVE-2025-7962?
Jakarta Mail version 2.2 is prone to a SMTP Injection vulnerability whereby attackers can exploit the handling of UTF-8 characters, specifically and , to manipulate email message flow. This flaw enables unauthorized separation of messages, leading to potential exploitation in email communications. Proper validation and sanitization methods should be employed to counteract these types of attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jakarta Mail 1.6.8
Jakarta Mail 2.0.2
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
1ue
blu3r
