CVE-2026-82973: PSYB0T Docker-Mailbox

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

Affected products

  • PSYB0T Docker-Mailbox: from 0.1.0, up to and including 0.4.12

Published 2026-09-29. Last modified 2026-09-29.