← Vulnerability feed

Vulnerability record · CVE-2026-61915 · published 9 September 2026

CVE-2026-61915: Cyrus imap double free vulnerability

Cyrus · Imap

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

7.1 CVSS 3.1 High EPSS 0.26% · top 84.2% CWE-415 · Double free
7.1CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Sep 2026Last modified by NVD

Description

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-61915 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18928Cyrus imap vulnerabilityCyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication con…EPSS 2.4%9.8CVE-2019-11356Cyrus imap out-of-bounds write vulnerabilityThe CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafte…EPSS 7.6%9.1CVE-2017-14230Cyrus imap improper input validation vulnerabilityIn the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused…EPSS 2.2%7.5CVE-2021-33582Cyrus imap vulnerabilityCyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-t…EPSS 3.1%7.5CVE-2015-8078Opensuse leap vulnerabilityInteger overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…EPSS 2.8%7.5CVE-2015-8077Cyrus imap vulnerabilityInteger overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…EPSS 3.3%7.5CVE-2015-8076Opensuse leap memory buffer overflow vulnerabilityThe index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s…EPSS 3.3%6.5CVE-2026-61908Cyrus imap out-of-bounds read vulnerabilityAn issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could at…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2026-61915), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.