CVE-2026-82973
Published 29 September 2026 · tracked since 30 September 2026
Description
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97395
- CVE-2026-71898 MEDIUM 4.3
- CVE-2026-71899
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-71897 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82804 HIGH 8.8
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823