Unknown · Inbox-Zero · CVE-2026-42865
**Name of the Vulnerable Software and Affected Versions**
Inbox Zero versions prior to 2.29.3
**Description**
The cleaner email stream endpoint used a shared Redis subscription listener. This configuration could result in thread events for one authenticated account being delivered to another authenticated account when both were using the cleaner feature simultaneously.
**Recommendations**
Update to version 2.29.3.