{"id":"CVE-2026-61908","title":"An issue was discovered in Cyrus IMAP before 3.12.4","summary":"An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could rea…","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-125"],"vendor":"cyrus","product":"imap","affected":["imap < 3.8.8","imap >= 3.9.0, < 3.10.4","imap >= 3.11.0, < 3.12.4"],"patched":["imap 3.12.4"],"published":"2026-09-09","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:24:33.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61908","references":[{"url":"https://cyrusimap.org","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-61908.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-61908"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526304"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-61908"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61908"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00224,"epssPercentile":0.13293,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T18:58:39.917684Z"},"ingestedAt":"2026-09-11T17:50:33.677Z","scores":{"nvd":3.1,"vendor":4.3},"slug":"CVE-2026-61908","body":"## Overview\n\nAn issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.\n\n## Affected\n\n- `imap < 3.8.8`\n- `imap >= 3.9.0, < 3.10.4`\n- `imap >= 3.11.0, < 3.12.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `imap 3.12.4`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-61908.json)","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}