A vulnerability was found in Courier IMAP. It has been declared as critical. This vulnerability affects the function alloc_search_key of the file searchinfo.C of the component Search Command Parser. The manipulation results in uncontrolled recursion.

This vulnerability is reported as CVE-2026-67194. The attack can be launched remotely. No exploit exists.

It is best practice to apply a patch to resolve this issue.