SMTP Injection Vulnerability in Jakarta Mail by Eclipse
CVE-2025-7962

6MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7962?

Jakarta Mail version 2.2 is prone to a SMTP Injection vulnerability whereby attackers can exploit the handling of UTF-8 characters, specifically and , to manipulate email message flow. This flaw enables unauthorized separation of messages, leading to potential exploitation in email communications. Proper validation and sanitization methods should be employed to counteract these types of attacks.

Affected Version(s)

Jakarta Mail 1.6.8

Jakarta Mail 2.0.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1ue
blu3r
.
CVE-2025-7962 : SMTP Injection Vulnerability in Jakarta Mail by Eclipse