Description
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
Published: 2026-09-09
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploit in Cyrus IMAP before 3.12.4 allows an authenticated user to craft a JMAP blob ID that causes the server to read past the end of an internal blob_headers array during download. The read can expose adjacent heap memory, resulting in the disclosure of data that is not intended to be visible to the authenticated user.

Affected Systems

Cyrus IMAP products from Cyrus IMAP for all releases prior to 3.12.4 are affected. This includes versions 3.10.x, 3.12.x (up to 3.12.3), and earlier 3.8.x releases.

Risk and Exploitability

The vulnerability has a CVSS score of 3.1, indicating low overall impact. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack requires a valid authenticated session and is therefore limited to users who have authorized JMAP access. While the read could leak private heap contents, the practical risk is constrained by the need for authentication and the low severity rating.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cyrus IMAP to version 3.12.4 or later to eliminate the out‑of‑bounds read.
  • Restrict JMAP access to only trusted and authorized users to reduce the potential for exploitation.
  • If an upgrade cannot be performed immediately, disable JMAP or remove the vulnerable functionality from the service.

Generated by OpenCVE AI on September 9, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read via JMAP Blob ID in Cyrus IMAP

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-125
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Cyrusimap Cyrus Imap
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T19:44:57.533Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:18:36.383

Modified: 2026-09-09T20:22:32.663

Link: CVE-2026-61908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T22:15:17Z

Weaknesses