{"id":"CVE-2026-82973","published":"2026-09-29T13:17:52.963","lastModified":"2026-09-29T21:36:39.547","description":"Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.","cvssScore":9.4,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","cwes":["CWE-93"],"vendors":[],"products":[],"references":[{"url":"https://gitlab.com/psyb0t/docker-mailbox/-/commit/90e6b492d42e011d0ba2c825795b33d054ee6636","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves improper handling of CRLF sequences in IMAP command construction, allowing remote unauthenticated attackers to inject additional commands, potentially leading to unauthorized access or data manipulation.","exploitability":"Exploitation is relatively straightforward when bearer-token authentication is not configured, requiring crafted folder, UID, or search values.","blast_radius":"If exploited, the impact could be significant, as it allows remote attackers to inject commands into an authenticated connection, potentially leading to data leakage or manipulation.","remediation":"Upgrade to psyb0t/docker-mailbox 0.4.13 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["imap","auth-bypass","remote","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:57:42.990Z"}}