Impact
An exploit in Cyrus IMAP before 3.12.4 allows an authenticated user to craft a JMAP blob ID that causes the server to read past the end of an internal blob_headers array during download. The read can expose adjacent heap memory, resulting in the disclosure of data that is not intended to be visible to the authenticated user.
Affected Systems
Cyrus IMAP products from Cyrus IMAP for all releases prior to 3.12.4 are affected. This includes versions 3.10.x, 3.12.x (up to 3.12.3), and earlier 3.8.x releases.
Risk and Exploitability
The vulnerability has a CVSS score of 3.1, indicating low overall impact. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack requires a valid authenticated session and is therefore limited to users who have authorized JMAP access. While the read could leak private heap contents, the practical risk is constrained by the need for authentication and the low severity rating.
OpenCVE Enrichment