HIGH7.5
GHSA-9342-92gg-6v29
Jakarta Mail vulnerable to SMTP Injection
Quick fix
GHSA-9342-92gg-6v29 — org.eclipse.angus:smtp: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.0.4</version> for org.eclipse.angus:smtpDetails
In Jakarta Mail 2.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.eclipse.angus:smtp
Introduced in:
0Fixed in: 2.0.4Fix
# pom.xml: bump <version>2.0.4</version> for org.eclipse.angus:smtpMaven/com.sun.mail:jakarta.mail
Introduced in:
0Fixed in: 1.6.8Fix
# pom.xml: bump <version>1.6.8</version> for com.sun.mail:jakarta.mailMaven/com.sun.mail:jakarta.mail
Introduced in:
2.0.0Fixed in: 2.0.2Fix
# pom.xml: bump <version>2.0.2</version> for com.sun.mail:jakarta.mailReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-7962[ADVISORY]
- https://github.com/jakartaee/mail-api/issues/765[WEB]
- https://github.com/jakartaee/mail-api/pull/760[WEB]
- https://github.com/eclipse-ee4j/angus-mail/commit/269099b652a0a5c2fa140f1296a18f0fbbea0d44[WEB]
- https://github.com/eclipse-ee4j/angus-mail[PACKAGE]
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/67[WEB]
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290[WEB]
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/290#note_5320539[WEB]
- http://www.openwall.com/lists/oss-security/2025/09/03/4[WEB]