External risk intelligence

CRLF Injection in psyb0t/docker-mailbox IMAP Command Construction

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-82973

The vulnerability affects a mail server component (IMAP), which is designed to be internet-facing by default to facilitate remote email retrieval. As a network-accessible service that functions as an entry point for mail communication, it is typically exposed to the public internet in standard deployment patterns.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in IMAP command handling could allow unauthenticated attackers to inject commands into email connections, potentially leading to unauthorized access or modification of email data if bearer-token authentication is not configured. The primary concern is to confirm if this specific technology is in use and, if so, assess the exposure.

  • Attackers can insert malicious commands into email.
  • This affects how systems handle email connections.
  • Confirm if this mail service is in use.

Attack Path

How an attacker could exploit the issue

A remote attacker can exploit this vulnerability by sending specially crafted input to the IMAP service when it's not secured with bearer-token authentication. This crafted input can lead to the injection of additional IMAP commands, potentially allowing the attacker to manipulate mailbox data or disrupt services.

  • Unauthenticated network access required.
  • Crafted folder, UID, or search values.
  • Inject commands; alter or access data.

Live Threat

Current exploitation, exposure, and threat context

When bearer-token authentication is not configured, a remote attacker could inject additional IMAP commands into an authenticated upstream mailbox connection. This could affect the integrity and availability of the mailbox service and potentially lead to unauthorized actions.

  • Mailbox service data and function at risk.
  • Via crafted IMAP command values.
  • Service disruption and data alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the psyb0t/docker-mailbox. The platform or infrastructure team likely manages this component, and the first step is to identify all instances, determine their reachability and criticality, and then confirm the accountable owner before planning remediation.

  • Platform or infrastructure teams own the issue.
  • Verify if bearer-token authentication is configured.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is psyb0t/docker-mailbox?

It is a containerized software solution designed to provide IMAP mail server functionality. People use it to manage and host email services within Docker environments, allowing clients to connect and retrieve messages over the network.

What does CWE-93 mean for CVE-2026-82973?

CWE-93 refers to the improper neutralization of CRLF sequences. In this vulnerability, it means the software fails to strip special line-break characters from user input. An attacker can use these characters to "break out" of the intended command structure and trick the server into executing unauthorized IMAP commands.

How does an attacker trigger this vulnerability?

An attacker sends crafted folder, UID, or search values to the IMAP service. If bearer-token authentication is not enabled, the system incorrectly interprets these inputs as legitimate new commands. Note that if bearer-token authentication is correctly configured, this specific command injection path is blocked.

Is my instance of docker-mailbox at risk?

Halo Surface Signal indicates this software is very likely internet-facing by design to facilitate remote email retrieval. If your instance is exposed to the public internet without bearer-token authentication, it is at higher risk because it remains accessible to remote, unauthenticated actors.

What should I do if I run this software?

First, identify all active instances of docker-mailbox in your infrastructure. Check your configuration to see if bearer-token authentication is active, as this is a key defense. Finally, consult the project's official guidance to update to a version beyond 0.4.13 where this flaw is addressed.

References