CVE-2019-18928: Cyrus Imap
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Affected products
- Cyrus Imap: from 2.5.0, before 2.5.14 (fixed in 2.5.14); from 3.0.0, before 3.0.12 (fixed in 3.0.12)
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
Published 2019-11-15. Last modified 2026-06-17.