← Back to search

CVE-2026-82973

9.4 CRITICAL

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
The flaw involves improper handling of CRLF sequences in IMAP command construction, allowing remote unauthenticated attackers to inject additional commands, potentially leading to unauthorized access or data manipulation.
Exploitability
Exploitation is relatively straightforward when bearer-token authentication is not configured, requiring crafted folder, UID, or search values.
Blast radius
If exploited, the impact could be significant, as it allows remote attackers to inject commands into an authenticated connection, potentially leading to data leakage or manipulation.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to psyb0t/docker-mailbox 0.4.13 or later.
imapauth-bypassremoteunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Weaknesses

CWE-93

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.