CVE-2026-67194
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. Courier IMAP has no overall command line length limit, making exploitation trivial. A single IMAP command with ~2500 nested parentheses overflows the 8MB default stack, causing SIGSEGV.
Published:Jul 29, 2026
Last Modified:Aug 14, 2026
EPS:Jul 29, 2026
EPSS Score:0.00305
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Courier-mta
Product
Courier Mail Server
Courier-mta
Courier Mail Server
Vendor
Svarshavchik
Product
Courier Imap
Svarshavchik
Courier Imap
Vendor
Svarshavchik
Product
Courier Mail Server
Svarshavchik
Courier Mail Server
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
