Cyrus SASL left with unfixed flaws and no active maintainers
Oracle engineer flags multiple open security issues after years without a release.
Alan Coopersmith of Oracle Solaris Engineering has drawn attention on the oss-security list to a set of publicly reported security problems in Cyrus SASL that still lack maintainer response.
The authentication library has not shipped a new version since 2022. Activity in the past year has been limited to documentation notes about cyrus-imapd releases, and former maintainers have said they are no longer involved.
The open reports cover memory leaks in password-handling paths, a one-byte heap out-of-bounds read while parsing SCRAM GS2 headers, a heap buffer overflow in the DIGEST-MD5 mechanism, and an SRP server authentication bypass that fails to reject a zero client public value. A separate build problem can produce a non-position-independent static library that registers no SASL mechanisms, breaking CRAM-MD5 and PIE linking.
Only one of the flaws has a CVE so far. Red Hat assigned CVE-2026-107161 to the DIGEST-MD5 heap buffer overflow (or an independent finding of the same issue).
Cyrus SASL underpins authentication for many mail and directory deployments, so prolonged silence leaves those systems exposed to known defects with no clear path to fixes.