CVE-2026-61908
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
- Published Sep 9, 2026
- CVSS 6.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available