CVE-2024-45626: Apache James Server

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.

Affected products

  • Apache James Server: before 3.7.6 (fixed in 3.7.6); from 3.8.0, before 3.8.2 (fixed in 3.8.2)

Published 2025-02-06. Last modified 2026-06-17.