---
id: CVE-2026-82973
title: >-
  Improper neutralization of CRLF sequences in IMAP command construction in
  psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker,
  when bearer-token authentication is not configured, to inject additional IMAP
  command…
summary: >-
  Improper neutralization of CRLF sequences in IMAP command construction in
  psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker,
  when bearer-token authentication is not configured, to inject additional IMAP
  command…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-93
vendor: psyb0t
product: docker-mailbox
affected:
  - docker-mailbox >= 0.1.0 <= 0.4.12
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:52.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82973'
references:
  - url: >-
      https://gitlab.com/psyb0t/docker-mailbox/-/commit/90e6b492d42e011d0ba2c825795b33d054ee6636
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T12:33:37.298Z'
---

## Overview

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
