Mail Project maintains a narrowly scoped mail application where the durable vulnerability signal centers on improper neutralization of CRLF sequences, a weakness characteristic of email protocol handling and message-formatting contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mail Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9102MEDIUM A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.m | Aug 18, 2025 | 5.5 | 20 | NO | NO |
CVE-2015-9097MEDIUM The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by | Jun 12, 2017 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mail Project.
Media articles that mention a CVE ID that affects a product developed by Mail Project — matched by CVE ID, not by vendor name.