CVE-2026-61908 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 JMAP Blob ID out-of-bounds

SecurityVulns

A vulnerability was found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 and classified as critical. This affects an unknown function of the component JMAP Blob ID Handler. Executing a manipulation can lead to out-of-bounds read.

This vulnerability is registered as CVE-2026-61908. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More