Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. Courier IMAP has no overall command line length limit, making exploitation trivial. A single IMAP command with ~2500 nested parentheses overflows the 8MB default stack, causing SIGSEGV.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-29 17:16
Updated : 2026-07-30 20:11
NVD link : CVE-2026-67194
Mitre link : CVE-2026-67194
CVE.ORG link : CVE-2026-67194
JSON object : View
Products Affected
No product.
CWE
CWE-674
Uncontrolled Recursion
