CVE-2025-7962CWE-147

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages

Medium · published July 21, 2025

CVSS v4.0
6.0
EPSS
1%
Percentile
53.3
In the wild
Unconfirmed
What it is

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

The record
Technical detail
CVSS v4.0
6.0 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
EPSS
0.00774 · 53.3th percentile
Weakness
CWE-147 · Improper Neutralization of Input Terminators
Published
2025-07-21T17:22Z
EPSS history
Timeline
  • 21 JUL 17:22Z
    In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages
    cvelistv5