What is CVE-2026-67194?
CVE-2026-67194 is a vulnerability in Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 that allows authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The flaw stems from insufficient handling of recursive descent in the `alloc_search_key` function of the SEARCH command parser. Upgrading to the fixed versions is strongly recommended.
Azərbaycanca: CVE-2026-67194, Courier IMAP (6.0.1-dən əvvəlki versiyalar) və Courier Mail Server-də (2.0.2-dən əvvəlki versiyalar) autentifikasiya olunmuş IMAP istifadəçilərinə dərin iç-içə mötərizəli SEARCH sorğuları göndərərək imapd prosesini çökdürməyə imkan verən boşluqdur. Bu zəiflik `alloc_search_key` funksiyasındakı rekursiv emal qüsurundan qaynaqlanır. Təsirə məruz qalan sistemlərdə Courier-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What function contains the flaw that causes CVE-2026-67194?
The CVE-2026-67194 vulnerability stems from insufficient handling of recursive descent in the `alloc_search_key` function of the SEARCH command parser in Courier IMAP and Courier Mail Server.
What is the recommended mitigation for CVE-2026-67194?
Upgrading Courier IMAP to version 6.0.1 or later and Courier Mail Server to version 2.0.2 or later is strongly recommended to mitigate CVE-2026-67194.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.