Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-46853.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "2.25" } ] } ]