cyrusimap Cyrus IMAP
6 known vulnerabilities in cyrusimap Cyrus IMAP, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-61915 CVSS 7.1 high An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a…
- CVE-2026-61911 CVSS 4.3 medium An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a…
- CVE-2026-61910 CVSS 5.0 medium An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An…
- CVE-2026-61909 CVSS 4.3 medium An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some…
- CVE-2026-61908 CVSS 6.5 medium An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated…
- CVE-2026-61907 CVSS 4.3 medium An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert…