stephan@srlabs.de wrote:
Note: After Cyrus SASL fixes the other issue #9123, I will request CVE id= 's for the two bugs and share them as a reference in the relevant issues = (#9123, #9124)
Usual practice for CVEs is not to make them public until fixes are released. In the future, you should tick the Major Security Issue button for potential CVEs so they can be handled privately before release.