CVE-2026-82973 PUBLISHED

Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox

Assigner: GitLab
Reserved: 31.08.2026 Published: 29.09.2026 Updated: 29.09.2026

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CVSS Score: 9.4

Product Status

Vendor psyb0t
Product docker-mailbox
Versions Default: unaffected
  • affected from 0.1.0 to 0.4.12 (incl.)

Solutions

Upgrade to version 0.4.13 or later.

Credits

  • Kietgboiz17 (@kietgboiz17, https://gitlab.com/kietgboiz17) finder

References

Problem Types

  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') CWE