CriticalCritical vulnerability
CVE-2026-82973 (CVSS 9.4)
NVD · officialPublished Sep 29, 2026Risk 50/100
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
Technical details
CVSS
9.4
AV:NetworkAC:LowPR:NoneUI:NoneC:LowI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source