NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-42865
Summary

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.

Publication Date May 12, 2026, 3:16 a.m.
Registration Date May 12, 2026, 4:14 a.m.
Last Update May 12, 2026, 3:16 a.m.
Related information, measures and tools
Common Vulnerabilities List