AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-37358

HIGH · CVSS 8.6 EPSS 0.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-06 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.6. It affects Apache. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2024-37358
Severity
HIGH
CVSS
8.6
EPSS
0.86%
Apache

Original NVD Description

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.

Related CVEs

Other vulnerabilities affecting the same vendor(s)