Unknown · Docker-Mailbox · CVE-2026-82973
**Name of the Vulnerable Software and Affected Versions**
docker-mailbox versions prior to 0.4.13
**Description**
Improper neutralization of CRLF (Carriage Return Line Feed) sequences during IMAP command construction allows a remote unauthenticated attacker to inject additional IMAP commands into an authenticated upstream mailbox connection. This occurs when bearer-token authentication is not configured and is triggered via crafted folder, UID, or search values.
**Recommendations**
Update to version 0.4.13 or later.