CVE-2025-7962High· 7.5▾ TwilightIn Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 0.8%
In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
jakarta_mail < 1.6.8jakarta_mail >= 2.0.0, < 2.0.2angus_mail < 2.0.4Upgrade past the affected range:
jakarta_mail 2.0.2angus_mail 2.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10543MediumEclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
CVE-2026-24457Critical· 9.1An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server
CVE-2026-1605High· 7.5In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This hap…
CVE-2026-12606Medium· 5.3Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling
CVE-2026-6790Medium· 5.3Eclipse Jetty: HTTP Authority/Host mismatch
CVE-2026-8384Medium· 5.3Eclipse Jetty: Path parameter traversal