Back

MEDIUM

cyrus-imapd: cyrus-imapd: JMAP email-header blob ID out-of-bounds index

Published Sep 9, 2026

Description

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.

Affected products

Remediation

Red Hat mitigation

To reduce the attack surface, restrict network access to the `cyrus-imapd` service to trusted clients or internal networks using firewall rules. For example, using `firewalld`: `sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="imap" protocol="tcp" accept'` `sudo firewall-cmd --reload` This may impact legitimate users who require remote access to the IMAP service. A service restart may be required for changes to take full effect.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2026
Updated Sep 10, 2026
Reserved Jul 13, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity Moderate
Public date Sep 10, 2026