{"id":"CVE-2025-7962","aliases":["GHSA-9342-92gg-6v29"],"url":"https://o3.security/vulnerability/CVE-2025-7962","summary":"Jakarta Mail vulnerable to SMTP Injection","details":"In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \\r and \\n UTF-8 characters to separate different messages.","published":"2025-07-21T17:22:12.520Z","modified":"2026-09-13T12:26:39.671279324Z","cvss":null,"epss":{"score":0.00774,"percentile":0.52973,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.eclipse.angus:smtp","fixedVersion":"2.0.4"},{"ecosystem":"Maven","name":"com.sun.mail:jakarta.mail","fixedVersion":"1.6.8"},{"ecosystem":"Maven","name":"com.sun.mail:jakarta.mail","fixedVersion":"2.0.2"}],"fix":{"url":"https://github.com/jakartaee/mail-api/pull/760","label":"jakartaee/mail-api#760"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/09/03/4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7962.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7962"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/cve-assignement/-/issues/67"},{"type":"WEB","url":"https://github.com/jakartaee/mail-api/issues/765"},{"type":"WEB","url":"https://github.com/jakartaee/mail-api/pull/760"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/angus-mail/commit/269099b652a0a5c2fa140f1296a18f0fbbea0d44"},{"type":"PACKAGE","url":"https://github.com/eclipse-ee4j/angus-mail"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290#note_5320539"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-13T12:26:39.671279324Z"}}