Impact
Netty's SMTP codec does not properly validate Carriage Return and Line Feed characters in the SMTP command-name field. Because command-name can contain untrusted user input, an attacker can embed CR/LF pairs to inject additional SMTP commands, a technique known as SMTP command smuggling. This can be used to relay mail through the affected server or to spoof sender or recipient email addresses, effectively enabling unauthorized email transmission. The flaw is classified as CWE-93 and, while it does not directly provide code execution, it allows misuse of the SMTP interface to conduct spam or phishing campaigns.
Affected Systems
Affected products include Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, and the Red Hat build of Apache Camel for Spring Boot version 4. All supported releases of these products that embed the vulnerable netty- codec-smtp component are potentially impacted, as the CVE data does not list specific version restrictions.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, showing that exploitation is currently considered unlikely. This vulnerability is not listed in the CISA KEV catalog. The vulnerability resides in a network-exposed SMTP codec, so the most likely attack vector is remote, involving crafted SMTP connections that deliver malicious command-name fields to trigger the smuggling behavior.
OpenCVE Enrichment