High severity8.6NVD Advisory· Published Feb 6, 2025· Updated Jun 17, 2026
CVE-2024-37358
CVE-2024-37358
Description
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.james.protocols:protocols-imapMaven | < 3.7.6 | 3.7.6 |
org.apache.james.protocols:protocols-imapMaven | >= 3.8.0, < 3.8.2 | 3.8.2 |
Affected products
3cpe:2.3:a:apache:james_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:james_server:*:*:*:*:*:*:*:*range: <3.7.6
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-56jp-w6vw-j3jwghsaADVISORY
- lists.apache.org/thread/1pxsh11v5s3fkvhnqvkmlqwt3fgpcrqcnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-37358ghsaADVISORY
- github.com/apache/james-project/commit/6dd3ad9ea1f6a9bc887d2c7af3f5aa30a60ec769ghsaWEB
- github.com/apache/james-project/commit/b2f3c06edfd37b409121bf04c56a6f026048a77eghsaWEB
News mentions
0No linked articles in our index yet.