CVE-2026-82973: Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
psyb0t/docker-mailboxto a version that resolves this vulnerability.Fixed in 0.4.13
Event History
Frequently Asked Questions
Under what configuration is this exploitable?
Exploitation requires bearer-token authentication not to be configured. In that condition, an unauthenticated remote attacker can target the IMAP command construction path.
What inputs can be used to inject additional IMAP commands?
Crafted folder, UID, or search values can carry the CRLF sequences used to inject additional commands into an authenticated upstream mailbox connection.
Which versions need remediation?
Versions before 0.4.13 are affected. Upgrade to 0.4.13 or later.