Denial of Service Vulnerability in Dovecot by Open-Xchange
CVE-2026-27852
7.5HIGH
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-27852?
An attacker with the ability to send emails to users can create specially crafted email messages that contain an excessive number of email addresses or MIME parameters in their headers. This leads to substantial memory consumption during the parsing of the message, ultimately resulting in a Denial of Service condition for the user when accessing the mail via IMAP. Although the message is delivered successfully, the excessive resource usage can cause the mail reading process to exceed memory limits and terminate unexpectedly.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
