Sceawere

Vulnerability Detail

CVE-2026-82973UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IMAP CRLF Injection in docker-mailbox

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.4
Creation Date
12h ago
Vendor
psyb0t
Product
docker-mailbox
Attack Type
CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.4",
  "pubDate": "2026-09-29T13:17:52.963Z",
  "pubdate": "2026-09-29T13:17:52.963Z",
  "executiveSummary": "The vulnerability identified in psyb0t/docker-mailbox (prior to version 0.4.13) concerns the improper neutralization of Carriage Return and Line Feed (CRLF) sequences during the construction of IMAP commands. This flaw represents a critical security deficiency in input sanitization, allowing an unauthenticated remote attacker to perform command injection against an authenticated upstream IMAP session. The impact is significant, as successful exploitation enables the execution of arbitrary IMAP commands, potentially leading to unauthorized mailbox access, data exfiltration, or modification of email state. The vulnerability is exploitable when bearer-token authentication is not explicitly configured, effectively bypassing standard authentication constraints by leveraging existing trusted connections. The risk implication is high, as it facilitates a protocol-level manipulation that can compromise the integrity and confidentiality of the communication between the docker-mailbox instance and the upstream IMAP server. Attackers do not require prior credentials for the target mailbox to initiate the injection, provided they can influence the folder, UID, or search parameters that the application processes.",
  "technicalDetails": "The root cause of this vulnerability lies in the failure of the docker-mailbox application to adequately sanitize user-supplied input before incorporating it into IMAP command strings. IMAP protocol commands rely on CRLF (\\r\\n) sequences as explicit message delimiters. By failing to filter or escape these characters, the application allows the injection of new commands into the underlying stream that communicates with the upstream IMAP server.\nThe exploitation method involves the manipulation of specific input parameters, namely folder names, UIDs, or search criteria. When an attacker provides a specially crafted string containing CRLF sequences, the application's command construction logic fails to treat the input as a literal value. Instead, the injected CRLF sequences terminate the legitimate command context, allowing the attacker-supplied content to be interpreted as a new, distinct IMAP command by the upstream server.\nThe attack flow proceeds as follows: First, the attacker identifies an entry point where user-supplied data (such as a folder path or search parameter) is passed directly to the IMAP command builder. Second, the attacker submits a payload structured with premature CRLF delimiters followed by malicious IMAP commands (e.g., 'FETCH', 'STORE', or 'EXPUNGE'). Third, because the application session is already authenticated to the upstream mailbox, the IMAP server treats the injected commands as part of the established, privileged session. Consequently, the injected operations execute with the permissions of the upstream-authenticated user.\nThis vulnerability is particularly severe because it effectively elevates an unauthenticated request into an authenticated action by piggybacking on an existing connection. The vulnerable component is the command generation module within versions of docker-mailbox prior to 0.4.13. The attack requires network access to the docker-mailbox instance and the absence of bearer-token authentication, which serves as a secondary barrier. The post-exploitation impact includes full control over the mailbox operations permitted by the authenticated session, allowing for the unauthorized retrieval of emails, deletion of messages, or the manipulation of mailbox flags without the attacker possessing valid user credentials for the mail account itself."
}
CVE-2026-82973: IMAP CRLF Injection in docker-mailbox (CRITICAL Severity, CVSS: 9.4) | Sceawere