CVE-2026-82973 UNKNOWN

CVE-2026-82973

Published: 2026-09-29

Description

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…