CVE-2026-61915: Cyrus Imap

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

Affected products

  • Cyrus Imap: before 3.8.8 (fixed in 3.8.8); from 3.9.0, before 3.10.4 (fixed in 3.10.4); from 3.11.0, before 3.12.4 (fixed in 3.12.4)

Published 2026-09-09. Last modified 2026-09-16.