No analysis available yet.
Vendor Solution
Upgrade to version 0.4.13 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values. | |
| Title | Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-09-29T14:35:12.368Z
Reserved: 2026-08-31T14:31:02.749Z
Link: CVE-2026-82973
Updated: 2026-09-29T14:35:08.219Z
Status : Received
Published: 2026-09-29T13:17:52.963
Modified: 2026-09-29T15:17:30.067
Link: CVE-2026-82973
No data.
OpenCVE Enrichment
No data.
-
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')