AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-40110

HIGH · CVSS 7.5 EPSS 2.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-40110
Severity
HIGH
CVSS
7.5
EPSS
2.86%
Apache

Original NVD Description

In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which enforce the use of RE2J regular expression engine to execute regex in linear time without back-tracking.