CVE Feed

    Dashboard / CVE / CVE-2026-67194

    CVE-2026-67194

    Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. Courier IMAP has no overall command line length limit, making exploitation trivial. A single IMAP command with ~2500 nested parentheses overflows the 8MB default stack, causing SIGSEGV.

    Published:Jul 29, 2026
    Last Modified:Aug 14, 2026
    EPS:Jul 29, 2026
    EPSS Score:0.00305
    CVSS Score:6.5

    Affected Products

    Vendor
    Courier-mta
    Product
    Courier Mail Server
    Vendor
    Svarshavchik
    Product
    Courier Imap
    Vendor
    Svarshavchik
    Product
    Courier Mail Server

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High