OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-82973

CRITICAL · CVSS 9.4 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Docker versions prior to 0.4.13 are vulnerable to an injection flaw that allows remote unauthenticated attackers to manipulate IMAP commands by exploiting improperly handled CRLF sequences. This could lead to unauthorized access and potential data breaches in authenticated mailbox connections, particularly if bearer-token authentication is not implemented. Organizations using affected Docker versions should prioritize immediate updates to mitigate this critical security risk.

CVE
CVE-2026-82973
Severity
CRITICAL
CVSS
9.4
EPSS
0.42%
Docker

Original NVD Description

Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.