CVE-2026-61908: Cyrus Imap

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.

Affected products

  • Cyrus Imap: before 3.8.8 (fixed in 3.8.8); from 3.9.0, before 3.10.4 (fixed in 3.10.4); from 3.11.0, before 3.12.4 (fixed in 3.12.4)

Published 2026-09-09. Last modified 2026-09-16.