CVE-2019-18928: Cyrus Imap

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Affected products

  • Cyrus Imap: from 2.5.0, before 2.5.14 (fixed in 2.5.14); from 3.0.0, before 3.0.12 (fixed in 3.0.12)
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only

Published 2019-11-15. Last modified 2026-06-17.