CVE-2025-7962: Eclipse Angus Mail

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

Affected products

  • Eclipse Angus Mail: before 2.0.4 (fixed in 2.0.4)
  • Eclipse Jakarta Mail: before 1.6.8 (fixed in 1.6.8); from 2.0.0, before 2.0.2 (fixed in 2.0.2)

Published 2025-07-21. Last modified 2026-06-23.