Vulnerability Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
- https://www.cyrusimap.org/imap/download/release-notes/index.html
FAQ
What is CVE-2026-47088?
CVE-2026-47088 is a vulnerability with a CVSS score of 3.1 (LOW). An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 82...
How severe is CVE-2026-47088?
CVE-2026-47088 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-47088?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.