PT-2025-30321 · Apache+3 · Jakarta Mail+3

Blu3R

·

Published

2025-07-21

·

Updated

2026-05-18

·

CVE-2025-7962

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jakarta Mail version 2.2
Description The software is susceptible to a SMTP Injection issue. This can be triggered by utilizing the carriage return (r) and newline ( ) UTF-8 characters to separate messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12843
ALT-PU-2025-13422
CLEANSTART-2026-IS05941
CLEANSTART-2026-KP10590
CVE-2025-7962
ECHO-FB57-1326-0BE8
GHSA-9342-92GG-6V29
OESA-2025-1987
OESA-2025-1988
OESA-2025-1989
OESA-2025-1990
OESA-2025-1991
OPENSUSE-SU-2025:15378-1
SUSE-SU-2025:03025-1
SUSE-SU-2025_03025-1

Affected Products

Alt Linux
Debian
Jakarta Mail
Suse