Description
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure (Out-of-Bounds Read)
Action: Apply patch
AI Analysis

Impact

An exploit in Cyrus IMAP before 3.12.4 allows an authenticated user to craft a JMAP blob ID that causes the server to read past the end of an internal blob_headers array during download. The read can expose adjacent heap memory, resulting in the disclosure of data that is not intended to be visible to the authenticated user.

Affected Systems

Cyrus IMAP products from Cyrus IMAP for all releases prior to 3.12.4 are affected. This includes versions 3.10.x, 3.12.x (up to 3.12.3), and earlier 3.8.x releases.

Risk and Exploitability

The vulnerability has a CVSS score of 3.1, indicating low overall impact. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack requires a valid authenticated session and is therefore limited to users who have authorized JMAP access. While the read could leak private heap contents, the practical risk is constrained by the need for authentication and the low severity rating.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cyrus IMAP to version 3.12.4 or later to eliminate the out‑of‑bounds read.
  • Restrict JMAP access to only trusted and authorized users to reduce the potential for exploitation.
  • If an upgrade cannot be performed immediately, disable JMAP or remove the vulnerable functionality from the service.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyrus
Cyrus imap
CPEs cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrus
Cyrus imap

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read via JMAP Blob ID in Cyrus IMAP cyrus-imapd: cyrus-imapd: JMAP email-header blob ID out-of-bounds index
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read via JMAP Blob ID in Cyrus IMAP

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-125
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T18:59:01.259Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61908

cve-icon Vulnrichment

Updated: 2026-09-10T18:58:50.439Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T20:18:36.383

Modified: 2026-09-16T15:24:33.310

Link: CVE-2026-61908

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T07:41:48Z

Links: CVE-2026-61908 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:45:17Z

Weaknesses