CVE-2024-21742: Apache James MIME4J

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.

Affected products

  • Apache James MIME4J: up to and including 0.8.9

Published 2024-02-27. Last modified 2026-06-17.