CVE-2025-7962
HighAdvisory
Published 21 Jul 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 54th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 104
- of 17,781 indexed, latest versions
- Container images
- 103
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Jakarta Mail vulnerable to SMTP Injection
Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 103 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jakarta.mailmaven | 1.6.3, 1.6.4, 1.6.5, 1.6.5-atlassian-2+4 more | 1.6.8, 2.0.2 | 76 |
| smtpmaven | 2.0.1, 2.0.2, 2.0.3 | 2.0.4 | 28 |
- OSV records
- GHSA-9342-92gg-6v29
Charts affected
104 by stars
Container images carrying it
103 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.