CVE-2026-61908
Undergoing Analysis Undergoing Analysis - In Progress

Heap Memory Exposure in Cyrus IMAP JMAP Blob Download

Vulnerability report for CVE-2026-61908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: MITRE

Description

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyrus imap to 3.12.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Cyrus IMAP before version 3.12.4. It involves a flaw where a JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could craft a blob ID like H<emailid>-<index> to read past the end of the internal blob_headers array during download, potentially exposing adjacent heap memory.

Detection Guidance

The vulnerability involves an out-of-bounds read in Cyrus IMAP's JMAP blob ID handling. To detect it, monitor for unusual JMAP requests with malformed blob IDs of the form H<emailid>-<index>. Check Cyrus IMAP logs for errors related to blob ID parsing or memory access violations. Ensure your Cyrus IMAP version is updated to 3.12.4 or later to mitigate this issue.

Impact Analysis

An attacker with authenticated access could exploit this to read sensitive data from adjacent memory locations. This may lead to unauthorized access to email content or other confidential information stored in memory. The impact is limited by the need for authentication and the low CVSS score indicating low exploitability.

Compliance Impact

This vulnerability could potentially expose sensitive email data stored in Cyrus IMAP due to out-of-bounds memory access. This may lead to unauthorized data disclosure, which could violate GDPR's data protection principles or HIPAA's confidentiality requirements if the exposed data includes personal or health information.

Mitigation Strategies

Upgrade Cyrus IMAP to version 3.12.4 or later to address the out-of-bounds heap memory exposure vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart