Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:NDefault status
unaffected
1.6.8
unaffected
2.0.2
unaffected
Description
In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
Problem types
CWE-147 Improper Neutralization of Input Terminators
Product status
1.6.8
2.0.2
Credits
1ue
blu3r
References
www.openwall.com/lists/oss-security/2025/09/03/4
gitlab.eclipse.org/security/cve-assignement/-/issues/67