Low severity3.1NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-61908
CVE-2026-61908
Description
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H-, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.