Denial of Service Vulnerability in Dovecot by Open-Xchange
CVE-2026-27852

7.5HIGH

What is CVE-2026-27852?

An attacker with the ability to send emails to users can create specially crafted email messages that contain an excessive number of email addresses or MIME parameters in their headers. This leads to substantial memory consumption during the parsing of the message, ultimately resulting in a Denial of Service condition for the user when accessing the mail via IMAP. Although the message is delivered successfully, the excessive resource usage can cause the mail reading process to exceed memory limits and terminate unexpectedly.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.