StackRadar

CVE-2025-7962

High

Advisory

Published 21 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 17,781 indexed, latest versions
Container images
103
deployed by those charts
Fix available
2 of 2
affected packages

Jakarta Mail vulnerable to SMTP Injection

Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 103 images.

Affected packageAffected versionsFixed inImages
jakarta.mailmaven1.6.3, 1.6.4, 1.6.5, 1.6.5-atlassian-2+4 more1.6.8, 2.0.276
smtpmaven2.0.1, 2.0.2, 2.0.32.0.428
OSV records
GHSA-9342-92gg-6v29

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-7962.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jakarta.mail@1.6.5
1.6.8

Open the chart page →

28,605
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2025-7962.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jakarta.mail@1.6.4
1.6.8

Open the chart page →

2,191
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-7962.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
smtp@2.0.2
2.0.4

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-7962.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jakarta.mail@1.6.5
1.6.8

Open the chart page →

6,016

Container images carrying it

103 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
smtp@2.0.3
2.0.4
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jakarta.mail@1.6.5
1.6.8
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
smtp@2.0.2
2.0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.