In apache-commons-email before 1.5, when a call-site passes a subject for an email that contains line-breaks, the caller can add arbitrary SMTP headers (CVE-2017-9801).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0322.json"