CVE-2021-26911

Source
https://cve.org/CVERecord?id=CVE-2021-26911
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26911.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-26911
Published
2021-02-17T21:15:12Z
Modified
2026-07-09T01:30:58Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:a:canarymail:canary_mail:3.20:*:*:*:*:iphone_os:*:*",
                "cpe:2.3:a:canarymail:canary_mail:3.21:*:*:*:*:iphone_os:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "3.20"
                },
                {
                    "last_affected":  "3.20"
                },
                {
                    "introduced":  "3.21"
                },
                {
                    "last_affected":  "3.21"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "canarymail:canary_mail"
        }
    ]
}
References

Affected packages

Git / github.com/canarymail/mailcore2

Affected ranges

Type
GIT
Repo
https://github.com/canarymail/mailcore2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Affected versions

0.*
0.1
0.2
0.2.pre1
0.3.pre1
0.5
0.5.1
0.6
0.6.1
0.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26911.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "58276512858806844581212893390254139380",
            "length":  2915
        },
        "id":  "CVE-2021-26911-b6c26fdd",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/canarymail/mailcore2/commit/45acb4efbcaa57a20ac5127dc976538671fce018",
        "target":  {
            "file":  "src/core/imap/MCIMAPSession.cpp",
            "function":  "IMAPSession::connect"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "183920586235143298930693814241404593940",
                "295238391851967688791346911655989942881",
                "188189554356135633814135185334812978196",
                "329706182311884316420429833290968507427"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2021-26911-ecff7eb9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/canarymail/mailcore2/commit/45acb4efbcaa57a20ac5127dc976538671fce018",
        "target":  {
            "file":  "src/core/imap/MCIMAPSession.cpp"
        }
    }
]
vanir_signatures_modified
"2026-07-09T01:30:58Z"

Git / github.com/mailcore/mailcore2

Affected ranges

Type
GIT
Repo
https://github.com/mailcore/mailcore2
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libmailcore:mailcore2:0.6.4:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0.6.4"
        },
        {
            "last_affected":  "0.6.4"
        }
    ],
    "source":  "CPE_STRING"
}

Affected versions

0.*
0.6.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26911.json"