PT-2026-60556 · Cyrusimap+3 · Cyrus Imap
CVE-2026-47088
·
Published
2026-07-16
·
Updated
2026-07-17
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
cyrus-imapd versions prior to 3.12.3
Description
An issue exists in the parsing of nested MIME comments. An authenticated IMAP user can craft an email message containing an RFC 822 comment that ends with a backslash. This causes the server to read past the end of the message in memory and access the heap, subsequently returning the leaked heap content to the user.
Recommendations
Update cyrus-imapd to version 3.12.3 or later.
Fix
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyrus Imap