Skip to content

Bump jakarta.mail to 1.6.8 (CVE-2025-7962) - #116

Open
KaterMikesch wants to merge 1 commit into
drewr:mainfrom
KaterMikesch:fix/cve-2025-7962-jakarta-mail-1.6.8
Open

Bump jakarta.mail to 1.6.8 (CVE-2025-7962)#116
KaterMikesch wants to merge 1 commit into
drewr:mainfrom
KaterMikesch:fix/cve-2025-7962-jakarta-mail-1.6.8

Conversation

@KaterMikesch

Copy link
Copy Markdown

CVE-2025-7962 is an SMTP Injection vulnerability in com.sun.mail:jakarta.mail versions < 1.6.8 (and < 2.0.2).\n\nUnicode characters like U+760D and U+760A, when converted from UTF-16 to bytes, produce raw CR (\r) and LF (\n) characters, enabling SMTP command injection.\n\nThis patch bumps jakarta.mail from 1.6.7 to 1.6.8, which includes the fix.\n\nSee: GHSA-9342-92gg-6v29

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant