PT-2026-102528 · Unknown · Docker-Mailbox
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
docker-mailbox versions prior to 0.4.13
Description
Improper neutralization of CRLF (Carriage Return Line Feed) sequences during IMAP command construction allows a remote unauthenticated attacker to inject additional IMAP commands into an authenticated upstream mailbox connection. This occurs when bearer-token authentication is not configured and is triggered via crafted folder, UID, or search values.
Recommendations
Update to version 0.4.13 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker-Mailbox