CVE-2026-82973

critical

Description

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

References

https://gitlab.com/psyb0t/docker-mailbox/-/commit/90e6b492d42e011d0ba2c825795b33d054ee6636

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88759

Details

Source: Mitre, NVD

Published: 2026-09-29

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 9.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.4

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00419