CVE Explorer
CVE-2026-47088
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Cyrus IMAP","vendor":"cyrusimap","versions":[{"lessThan":"3.12.3","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7657245b55f67329044a6f827d14c7b7ad44f9b8f98f285cc526535fdd35e497 · sha256:29e24602c211db07… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7657245b55f67329044a6f827d14c7b7ad44f9b8f98f285cc526535fdd35e497 · sha256:29e24602c211db07… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-126","description":"CWE-126 Buffer Over-read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7657245b55f67329044a6f827d14c7b7ad44f9b8f98f285cc526535fdd35e497 · sha256:29e24602c211db07… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7657245b55f67329044a6f827d14c7b7ad44f9b8f98f285cc526535fdd35e497 · sha256:29e24602c211db07… · /containers/cna/references/1
{"url":"https://www.cyrusimap.org/imap/download/release-notes/index.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7657245b55f67329044a6f827d14c7b7ad44f9b8f98f285cc526535fdd35e497 · sha256:29e24602c211db07… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.