Cyrusimap maintains authentication and mail-server components (Cyrus SASL and Cyrus IMAP) that are embedded in enterprise messaging and authentication infrastructures, with a narrow but strategically positioned product scope. Observed vulnerabilities cluster around resource exhaustion and input-handling issues, including improper throttling, buffer-size miscalculations, off-by-one errors, and SQL injection in query processing—patterns reflecting the parsing and state-management demands of mail and authentication protocols. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyrusimap over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1347CRITICAL Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during | Dec 18, 2002 | 9.8 | 32 | NO | NO |
CVE-2026-47084MEDIUM An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LO | Jul 16, 2026 | 6.5 | 30 | NO | NO |
CVE-2022-24407HIGH In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. | Feb 24, 2022 | 8.8 | 30 | NO | NO |
CVE-2019-19906HIGH cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ult | Dec 19, 2019 | 7.5 | 29 | NO | NO |
CVE-2026-47082MEDIUM An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to | Jul 16, 2026 | 5.4 | 27 | NO | NO |
CVE-2026-47083MEDIUM An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could e | Jul 16, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-47089MEDIUM An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against | Jul 16, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-47085MEDIUM An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's accoun | Jul 16, 2026 | 4.0 | 24 | NO | NO |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH | Jul 16, 2026 | 3.5 | 23 | NO | NO |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continue | Jul 16, 2026 | 3.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyrusimap.
Media articles that mention a CVE ID that affects a product developed by Cyrusimap — matched by CVE ID, not by vendor name.