CVE-2026-61908

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*

History

16 Sep 2026, 15:24

Type Values Removed Values Added
First Time Cyrus
Cyrus imap
CPE cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
References () https://cyrusimap.org - () https://cyrusimap.org - Product
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html - Release Notes
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html - Release Notes
References () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html - () https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html - Release Notes

Information

Published : 2026-09-09 20:18

Updated : 2026-09-16 15:24


NVD link : CVE-2026-61908

Mitre link : CVE-2026-61908

CVE.ORG link : CVE-2026-61908


JSON object : View

Products Affected

cyrus

  • imap
CWE
CWE-125

Out-of-bounds Read